CVE-2018-6393
Dashboard / Vulnerabilities / CVE-2018-6393
CVE-2018-6393
Published: 29 Jan 2018Last Modified: 8 Jul 2026
Summary:
Details: FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables ... [or] run shell scripts ... once ... logged in to the administration interface; there is no need to try to find input validation errors.
References: http://www.securityfocus.com/bid/102854, http://code610.blogspot.com/2018/01/post-auth-sql-injection-in-freepbx.html, https://github.com/c610/tmp/blob/master/sqlipoc-freepbx-14.0.1.24-req.txt
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 4bcffdacdf1a208ac2806b8e932fc3ac50abe8f9
Fixed -None
Affected versions
14.0.1.24
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
