CVE-2024-58294: FreePBX 16 Authenticated Remote Code Execution via API Module
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58294?
CVE-2024-58294 is rated as a critical severity vulnerability due to its potential for authenticated remote code execution.
How do I fix CVE-2024-58294?
To mitigate CVE-2024-58294, update FreePBX 16 to the latest version that patches this vulnerability.
What causes CVE-2024-58294?
CVE-2024-58294 is caused by the improper validation of user input in the API module, allowing command injection through the 'generatedocs' endpoint.
Who is affected by CVE-2024-58294?
CVE-2024-58294 affects users of FreePBX 16 who have authenticated access to the API module.
What are the potential impacts of CVE-2024-58294?
The potential impacts of CVE-2024-58294 include unauthorized remote command execution, leading to system compromise.