CVE-2023-43336: Sangoma FreePBX
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
Affected products
- Sangoma FreePBX: before 15.0.16 (fixed in 15.0.16); from 16.0.2, before 16.0.17 (fixed in 16.0.17); before 15.0.18 (fixed in 15.0.18); from 16.0.2, before 16.0.40 (fixed in 16.0.40)
Published 2023-11-02. Last modified 2026-07-09.