CVE-2020-10666: Command Injection
Published May 31, 2021
·Updated
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.
Affected Software
4 affected components
Sangoma restapps>=13.0<=13.0.93.2
Sangoma restapps>=14.0<=14.0.22.2
Sangoma restapps>=15.0<=15.0.19.2
Sangoma FreePBX
Event History
May 31, 2021
CVE Published
via MITRE·11:40 AM
Data Sourced
via MITRE·11:40 AM
Description
Frequently Asked Questions
1
What is CVE-2020-10666?
CVE-2020-10666 is a vulnerability in the restapps module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2.
2
What is the severity of CVE-2020-10666?
CVE-2020-10666 has a severity rating of 9.8 (critical).
3
How does CVE-2020-10666 allow remote code execution?
CVE-2020-10666 allows remote code execution via a URL variable to an AMI command.
4
Which software versions are affected by CVE-2020-10666?
Versions 13, 14, and 15 through 15.0.19.2 of the restapps module for Sangoma FreePBX and PBXact are affected by CVE-2020-10666.
5
Where can I find more information about CVE-2020-10666?
You can find more information about CVE-2020-10666 on the FreePBX Wiki page.