CVE-2018-15891: FreePBX

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.

Affected products

  • FreePBX FreePBX: version 15.0.1 only
  • Sangoma FreePBX: before 13.0.122.43 (fixed in 13.0.122.43); from 14.0.0, before 14.0.18.34 (fixed in 14.0.18.34); from 15.0.0, up to and including 15.0.1; version 15.0.1 only

Published 2019-06-20. Last modified 2026-06-17.