SB2014021802 - Permissions, Privileges, and Access Controls in FreePBX



SB2014021802 - Permissions, Privileges, and Access Controls in FreePBX

Published: February 18, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014021802
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-1903)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.


Remediation

Install update from vendor's website.