First published: Thu Nov 02 2023(Updated: )
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sangoma FreePBX | <15.0.16 | |
Sangoma FreePBX | >=16.0.2<16.0.17 | |
Sangoma FreePBX | <15.0.18 | |
Sangoma FreePBX | >=16.0.2<16.0.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-43336.
The severity level of CVE-2023-43336 is high with a severity value of 8.8.
Sangoma Technologies FreePBX versions before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 are affected.
CVE-2023-43336 contains an access control issue via a modified parameter value, such as changing extension=self to extension=101.
To fix CVE-2023-43336, it is recommended to update Sangoma Technologies FreePBX to cdr 15.0.18, 16.0.40, 15.0.16, or 16.0.17 depending on the affected version.