admin/libraries/view.functions.php in FreePBX 2.9 prior to 2.9.0.14, 2.10 prior to 2.10.1.15, 2.11 prior to 2.11.0.23, and 12 prior to 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote malicious users to execute arbitrary PHP code via the function and args parameters to admin/config.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
freepbx freepbx 2.11 |
||
freepbx freepbx 2.10 |
||
sangoma freepbx 2.9 |
||
freepbx freepbx 2.12 |