First published: Mon Dec 02 2024(Updated: )
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreePBX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53564 is considered to be of high severity due to its ability for high-privilege administrators to upload unwanted files.
To fix CVE-2024-53564, ensure that uploaded files are properly verified and restrict the ability to upload files to trusted users only.
CVE-2024-53564 affects FreePBX version 17.0.19.17 and potentially any configurations allowing high-privilege administrators to upload files.
Attackers with high-privilege access can exploit CVE-2024-53564 to upload malicious files through the FreePBX module upload feature.
CVE-2024-53564 primarily poses a risk to high-privilege administrators, as standard users do not have the access required to exploit this vulnerability.