First published: Mon Mar 16 2020(Updated: )
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sangoma FreePBX | <13.0.92 | |
Sangoma FreePBX | >=14.0.0.0<14.0.38.3 | |
Sangoma FreePBX | >=15.0.0.0<15.0.13.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19538 is a Remote Command Execution vulnerability in Sangoma FreePBX 13 through 15 and sysadmin modules.
CVE-2019-19538 has a severity score of 7.2, which is considered high.
Sangoma FreePBX versions 13.0.92 up to exclusive, 14.0.0.0 up to 14.0.38.3 (exclusive), and 15.0.0.0 up to 15.0.13.6 (exclusive) are affected.
CVE-2019-19538 allows an attacker to execute remote commands, resulting in privilege escalation.
To fix CVE-2019-19538, it is recommended to update the Sangoma FreePBX and sysadmin modules to the latest versions available.