CVE-2024-53564: Malicious File Upload
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53564?
CVE-2024-53564 is considered to be of high severity due to its ability for high-privilege administrators to upload unwanted files.
How do I fix CVE-2024-53564?
To fix CVE-2024-53564, ensure that uploaded files are properly verified and restrict the ability to upload files to trusted users only.
Who is affected by CVE-2024-53564?
CVE-2024-53564 affects FreePBX version 17.0.19.17 and potentially any configurations allowing high-privilege administrators to upload files.
What can attackers do with CVE-2024-53564?
Attackers with high-privilege access can exploit CVE-2024-53564 to upload malicious files through the FreePBX module upload feature.
Is CVE-2024-53564 a risk for standard users?
CVE-2024-53564 primarily poses a risk to high-privilege administrators, as standard users do not have the access required to exploit this vulnerability.