#VU114554 SQL injection in FreePBX - CVE-2025-57819
Published: August 29, 2025 / Updated: October 31, 2025
FreePBX
FreePBX
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient sanitization of user-supplied data within the endpoint module. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands, leading to system compromise.
Note, the vulnerability is being actively exploited in the wild since August 21, 2025.