Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-59429— FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page

EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-59429

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page
Source: NVD (National Vulnerability Database)
Vulnerability Description
FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripting vulnerability is present on the Asterisk HTTP Status page. The Asterisk HTTP status page is exposed by FreePBX and is available by default on version 16 via any bound IP address at port 8088. By default on version 17, the binding is only to localhost IP, making it significantly less vulnerable. The vulnerability can be exploited by unauthenticated attackers to obtain cookies from logged-in users, allowing them to hijack a session of an administrative user. The theft of admin session cookies allows attackers to gain control over the FreePBX admin interface, enabling them to access sensitive data, modify system configurations, create backdoor accounts, and cause service disruption. This issue has been patched in version 16.0.68.39 for FreePBX 16 and version 17.0.18.38 for FreePBX 17.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
FreePBX 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FreePBX(前称Asterisk Management Portal)是FreePBX项目的一套通过GUI(基于网页的图形化接口)配置Asterisk(IP电话系统)的工具。 FreePBX 16 16.0.68.39之前版本和FreePBX 17 17.0.18.38之前版本存在跨站脚本漏洞,该漏洞源于Asterisk HTTP状态页面存在反射型跨站脚本,可能导致会话劫持和系统控制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
FreePBXcore < 16.0.68.39 -

II. Public POCs for CVE-2025-59429

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-59429

登录查看更多情报信息。

Same Patch Batch · FreePBX · 2025-10-14 · 4 CVEs total

CVE-2025-59051FreePBX Endpoint Manager command injection via Network Scanning feature
CVE-2025-61678FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand par
CVE-2025-61675FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configurati

IV. Related Vulnerabilities

V. Comments for CVE-2025-59429

No comments yet


Leave a comment