#VU5362 Code injection in FreePBX - CVE-2014-7235
Published: January 24, 2017
FreePBX
FreePBX
Description
The weakness exists due to an error in the legacy FreePBX ARI Framework module/Asterisk Recording Interface (ARI). A remote attacker can bypass the authentication process and execute arbitrary code with administrative privileges.
Successful exploitation results in arbitrary code execution on the vulnerable system.
Note: this vulnerability was being actively exploited.