HomeSangomaCVE-2024-53564

CVE-2024-53564

LOW
2.2CVSS
Published: 2024-12-02
Updated: 2025-09-23
AI Analysis

Description

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
network
Complexity
high
Privileges
high
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
none
Weaknesses
CWE-434

Metadata

Primary Vendor
SANGOMA
Published
12/2/2024
Last Modified
9/23/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

sangoma : freepbx

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-53564 | LOW Severity | CVEDatabase.com | CVEDatabase.com