Description
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42260 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4. |
References
History
Tue, 01 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx endpoint Manager |
|
| CPEs | cpe:2.3:a:freepbx:endpoint_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freepbx
Freepbx endpoint Manager |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4. | |
| Title | OSS Endpoint Manager allows unauthorized access to read system files | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-13T21:52:08.659Z
Reserved: 2024-09-17T17:42:37.029Z
Link: CVE-2024-47071
Updated: 2024-10-01T16:11:09.553Z
Status : Deferred
Published: 2024-10-01T16:15:09.637
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-47071
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD