CVE-2014-1903: High severity FreePBX FreePBX vulnerability
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 2.9.0.14 - Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 2.10.1.15 - Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 2.11.0.23 - Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 12.0.1alpha22
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1903?
CVE-2014-1903 has a high severity due to its potential for remote code execution.
How do I fix CVE-2014-1903?
To fix CVE-2014-1903, update FreePBX to version 2.9.0.14, 2.10.1.15, 2.11.0.23, or later.
What software versions are affected by CVE-2014-1903?
CVE-2014-1903 affects FreePBX versions 2.9, 2.10, 2.11, and 2.12 prior to their respective patch releases.
What is the nature of the vulnerability in CVE-2014-1903?
CVE-2014-1903 allows remote attackers to execute arbitrary PHP code due to insufficient restrictions on accessible functions.
Can CVE-2014-1903 be exploited without authentication?
Yes, CVE-2014-1903 can be exploited by unauthenticated remote attackers.