CVE-2024-58294

Source
https://cve.org/CVERecord?id=CVE-2024-58294
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58294.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58294
Published
2025-12-11T22:15:50.423Z
Modified
2026-03-13T11:31:09.479643Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58294.json"