PoC Archive PoC Archive

tag

Freepbx

Critical
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819· Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module) patched
Critical
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039· FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems patched
Critical
FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
CVE-2026-46376 (GHSA-m55x-h47x-v3gx)· FreePBX (userman module) — User Control Panel (UCP) patched