FreePBX 15, 16, and 17 contain a remote code execution caused by insufficiently sanitized user-supplied data in endpoints, letting unauthenticated attackers manipulate the database and execute code remotely, exploit requires no authentication.
id: CVE-2025-57819
info:
name: FreePBX - Remote Code Execution
author: watchtowr,pussycat0x,Dhi
...