Impact
The vulnerability allows a privileged reader to see plaintext passwords and secrets that the application writes to the audit log. The affected functions expose these secrets in the JSON payload, which is then persisted to the audit detail field. An attacker who can query the audit log with PERM_READ privileges can recover the stored credentials, potentially compromising the underlying PBX system.
Affected Systems
The issue is present in Frogman version 1.6.1 and earlier. The product is provided by mwtcmi under the Frogman project. Users of the 1.6.1 release or earlier running the headless PBX control via MCP or HTTP API are impacted until they upgrade to version 1.6.2 or later.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1%, suggesting that exploitation is not widely observed. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an actor to have read access to the audit log, which can be achieved by any user with PERM_READ permissions. The attacker can retrieve the credentials contained in the oc_audit_log.detail field and use them to gain further access to the PBX system.
OpenCVE Enrichment