Security Advisory

CVE-2025-59056

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-15 21:04:07
Last updated 2026-02-13 22:00:54
Assigner GitHub_M
State PUBLISHED

Description

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the modules database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.