2020-08-17 SQL Injection In cdr module
SEC-2020-007
SQL Injection: CVE-TBD
Overview:
A SQL Injection vulnerability exists in FreePBX 13, 14, and 15 between cdr module versions.
Discovered By:
NCC Group Security Advisory
Author : Bill Marquette <bill.marquette[at]nccgroup[dot]com>
Impact:
CVSS Base Score:7.6
Impact Subscore:6.0
Exploitability Subscore:1.0
CVSS Temporal Score:7.2
CVSS Environmental Score:6.0
Modified Impact Subscore:5.9
Overall CVSS Score:6.0
Vulnerable software and versions:
FreePBX13 - module: cdr, affected version: <=13.0.33 , fixed version: 13.0.35
FreePBX14 - module: cdr, affected version: <=14.0.5.20 , fixed version: 14.0.5.22
FreePBX15 - module: cdr, affected version: <=15.0.17.1 , fixed version: 15.0.17.2
Related Information:
Official Bug ticket : https://issues.freepbx.org/browse/FREEI-1763
Further Details:
FreePBX 13, 14, & 15 were susceptible to a SQL Injection vulnerability in the cdr module that allowed access and modification to FreePBX database tables.
The Sangoma and FreePBX team has deemed this a serious security issue, after the exploit was discovered in the wild, and immediately released a patch to resolve it. We strongly encourage all users of FreePBX 13 to upgrade to the latest cdr version. This can be done from the Module Admin GUI or fwconsole. For more information on using Module Admin, please see https://sangomakb.atlassian.net/wiki/spaces/PG/pages/20023939/Module+Admin+User+Guide .
Sangoma takes security seriously and requests that any future FreePBX security issue be reported at security@freepbx.org.