CVE-2018-15892: FreePBX Disa

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.

Affected products

  • FreePBX Disa: before 13.0.6.2 (fixed in 13.0.6.2)

Published 2019-06-20. Last modified 2026-06-17.