CVE-2020-10666

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
31/05/2021
Last modified:
12/07/2022

Description

The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sangoma:restapps:*:*:*:*:*:*:*:* 13.0 (including) 13.0.93.2 (including)
cpe:2.3:a:sangoma:restapps:*:*:*:*:*:*:*:* 14.0 (including) 14.0.22.2 (including)
cpe:2.3:a:sangoma:restapps:*:*:*:*:*:*:*:* 15.0 (including) 15.0.19.2 (including)
cpe:2.3:a:sangoma:freepbx:-:*:*:*:*:*:*:*