OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
History

Tue, 01 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Freepbx
Freepbx endpoint Manager
CPEs cpe:2.3:a:freepbx:endpoint_manager:*:*:*:*:*:*:*:*
Vendors & Products Freepbx
Freepbx endpoint Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
Title OSS Endpoint Manager allows unauthorized access to read system files
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-01T15:40:46.257Z

Updated: 2024-10-01T16:15:01.398Z

Reserved: 2024-09-17T17:42:37.029Z

Link: CVE-2024-47071

cve-icon Vulnrichment

Updated: 2024-10-01T16:11:09.553Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-01T16:15:09.637

Modified: 2024-10-04T13:51:25.567

Link: CVE-2024-47071

cve-icon Redhat

No data.