SQL Injection: CVE-TBD
A SQL Injection vulnerability exists in FreePBX 13, 14, and 15 between cdr module versions.
NCC Group Security Advisory
Author : Bill Marquette <bill.marquette[at]nccgroup[dot]com>
CVSS Base Score:7.6
CVSS Temporal Score:7.2
CVSS Environmental Score:6.0
Modified Impact Subscore:5.9
Overall CVSS Score:6.0
Vulnerable software and versions:
FreePBX13 - module: cdr, affected version: <=13.0.33 , fixed version: 13.0.35
FreePBX14 - module: cdr, affected version: <=18.104.22.168 , fixed version: 22.214.171.124
FreePBX15 - module: cdr, affected version: <=126.96.36.199 , fixed version: 188.8.131.52
Official Bug ticket : https://issues.freepbx.org/browse/FREEI-1763
FreePBX 13, 14, & 15 were susceptible to a SQL Injection vulnerability in the cdr module that allowed access and modification to FreePBX database tables.
The Sangoma and FreePBX team has deemed this a serious security issue, after the exploit was discovered in the wild, and immediately released a patch to resolve it. We strongly encourage all users of FreePBX 13 to upgrade to the latest cdr version. This can be done from the Module Admin GUI or fwconsole. For more information on using Module Admin, please see http://wiki.freepbx.org/display/FPG/Module+Admin+User+Guide.
Sangoma takes security seriously and requests that any future FreePBX security issue be reported at firstname.lastname@example.org.