SB2025082906 - SQL injection in FreePBX



SB2025082906 - SQL injection in FreePBX

Published: August 29, 2025 Updated: October 31, 2025

Security Bulletin ID SB2025082906
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) SQL injection (CVE-ID: CVE-2025-57819)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient sanitization of user-supplied data within the endpoint module. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands, leading to system compromise.

Note, the vulnerability is being actively exploited in the wild since August 21, 2025.


Remediation

Install update from vendor's website.