peter bassill · operator
$ cve CVE-2014-1903 JSON

CVE-2014-1903 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 52.8% (pctl 99)

Patch early

A public exploit exists.

Description

admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS52.78% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2014-02-18
Last modified2026-06-17

Affected (2)

VendorProduct
freepbxfreepbx
sangomafreepbx

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD