216.73.217.24

CVE-2026-44239

· Published 29/05/2026 14:16 · Modified 29/05/2026 15:06

Labels: CVE-2026-44239 2026-05-29CVE-2026-44239CWE-98[email protected]

Essential information

Published
29/05/2026 14:16
Modified
29/05/2026 15:06
Author
Creator
CVSS
7.6 HIGH (v3) 7.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
freepbx / freepbx cpe:2.3:a:freepbx:freepbx:16.0.22:*:*:*:*:*:*:*
freepbx / freepbx cpe:2.3:a:freepbx:freepbx:17.0.5:*:*:*:*:*:*:*

References