CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Multiple critical vulnerabilities in FreePBX, including SQL injection, arbitrary file upload, and authentication bypass flaws, have been patched. These flaws could lead to remote code execution (RCE) under certain configurations. The vulnerabilities were discovered by Horizon3.ai and reported to the project maintainers on September 15, 2025. Patches were released in October and December 2025.

Timeline

  1. 15.12.2025 16:32 1 articles · 2h ago

    FreePBX Patches Critical Vulnerabilities Enabling RCE

    Multiple critical vulnerabilities in FreePBX, including SQL injection, arbitrary file upload, and authentication bypass flaws, have been patched. These flaws could lead to remote code execution (RCE) under certain configurations. The vulnerabilities were discovered by Horizon3.ai and reported to the project maintainers on September 15, 2025. Patches were released in October and December 2025.

    Show sources

Information Snippets