Impact
The vulnerability is an unauthenticated SQL injection in the FreePBX missedcall module that allows an attacker to insert arbitrary SQL when a monitored extension goes unanswered. This flaw can corrupt the database and modify administrator accounts, giving the attacker full administrative control over the system. The weakness is a classic SQL injection, mapped to CWE‑89, and its impact is the ability to take over a FreePBX instance without authentication.
Affected Systems
FreePBX missedcall module versions 16.0.0 through 16.0.10 (prior to the 16.0.11 fix) and any 17.0.x releases before 17.0.4 are affected. Versions 16.0.11 and 17.0.4 onward contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. No EPSS data is available, so the likelihood of exploitation cannot be quantified; the flaw remains a high‑risk vulnerability because it can be triggered without authentication and can lead to total system compromise. Since the vulnerability is not listed in CISA KEV, there is currently no publicly confirmed exploitation, but the potential for abuse is high. The attack vector is inferred to be remote, over the public network, by sending specially crafted SIP From headers to the missedcall module.
OpenCVE Enrichment