First published: Thu Nov 21 2019(Updated: )
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sangoma FreePBX | >=13.0.0.0<=13.0.197.13 | |
Sangoma FreePBX | >=14.0.0.0<=14.0.13.11 | |
Sangoma FreePBX | >=15.0.0.0<=15.0.16.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19006 is a vulnerability in Sangoma FreePBX versions 14.0.13.11 and below, 13.0.197.13 and below, and 15.0.16.26 and below that allows incorrect access control.
CVE-2019-19006 has a severity rating of 9.8 out of 10, which is considered critical.
Versions 14.0.13.11 and below, 13.0.197.13 and below, and 15.0.16.26 and below of Sangoma FreePBX are affected by CVE-2019-19006.
The CWE ID for CVE-2019-19006 is CWE-287.
To fix CVE-2019-19006, it is recommended to update Sangoma FreePBX to a version that is not affected by the vulnerability.