Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma freepbx |
|
| CPEs | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sangoma
Sangoma freepbx |
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx security-reporting |
|
| Vendors & Products |
Freepbx
Freepbx security-reporting |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5. | |
| Title | FreePBX: Authenticated Local File Inclusion in Dashboard Module | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:58:06.273Z
Reserved: 2026-05-05T15:42:40.519Z
Link: CVE-2026-44239
Updated: 2026-06-01T19:58:02.670Z
Status : Analyzed
Published: 2026-05-29T14:16:27.363
Modified: 2026-06-01T18:41:28.630
Link: CVE-2026-44239
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:30:04Z