FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables ... [or] run shell scripts ... once ... logged in to the administration interface; there is no need to try to find input validation errors.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:01:49.262Z
Reserved: 2018-01-29T00:00:00
Link: CVE-2018-6393
No data.
Status : Modified
Published: 2018-01-29T20:29:00.420
Modified: 2024-11-21T04:10:37.537
Link: CVE-2018-6393
No data.
OpenCVE Enrichment
No data.
Weaknesses