Summary
FreePBX module tts (Text to Speech) is vulnerable to SQL injection by authenticated users with administrator access.
Details
Authenticated users with administrative access to the Administrator Control Panel (ACP) can leverage this SQL injection vulnerability to extract sensitive information from the database and execute code on the system as the asterisk user with chained elevation to root privileges.
Mitigation
Update to the latest version of the tts module.
Scoring
CVSS 4.0 Base vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS 4.0 more complete vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/MAT:P/MPR:H/U:Green
Current CVSS v4.0 Base score is 8.6 (High)
Current CVSS v4.0 more complete score is 4.8 (Medium)
Alternative CVSS v4.1 score is 0.2 (Low)
See details on scoring on the FreePBX blog at https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80/
Summary
FreePBX module tts (Text to Speech) is vulnerable to SQL injection by authenticated users with administrator access.
Details
Authenticated users with administrative access to the Administrator Control Panel (ACP) can leverage this SQL injection vulnerability to extract sensitive information from the database and execute code on the system as the
asteriskuser with chained elevation torootprivileges.Mitigation
Update to the latest version of the
ttsmodule.Scoring
CVSS 4.0 Base vector string:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVSS 4.0 more complete vector string:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/MAT:P/MPR:H/U:GreenCurrent CVSS v4.0 Base score is 8.6 (High)
Current CVSS v4.0 more complete score is 4.8 (Medium)
Alternative CVSS v4.1 score is 0.2 (Low)
See details on scoring on the FreePBX blog at https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80/