CVE-2019-19538: Sangoma FreePBX
High severity, CVSS 7.2. EPSS: 3.1% chance of exploitation in the next 30 days.
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
Affected products
- Sangoma FreePBX: before 13.0.92 (fixed in 13.0.92); from 14.0.0.0, before 14.0.38.3 (fixed in 14.0.38.3); from 15.0.0.0, before 15.0.13.6 (fixed in 15.0.13.6)
Published 2020-03-16. Last modified 2026-06-17.