#VU65373 Input validation error in Phone Apps - CVE-2021-45461

 

#VU65373 Input validation error in Phone Apps - CVE-2021-45461

Published: December 22, 2021


Vulnerability identifier: #VU65373
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2021-45461
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Phone Apps
Software vendor:
FreePBX

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in the Phone Apps (restapps) module for FreePBX. A remote attacker can send specially crafted input to the application and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links