FreePBX CDR Module SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the FreePBX CDR (Call Data Record) module, affecting versions prior to 16.0.49 and 17.0.7. The vulnerability arises from inadequate input sanitization of certain LIMIT parameters in SQL queries, allowing user-controlled input to be directly injected into the database queries. This could enable an attacker to manipulate or view database information. Exploitation requires authentication with a known username.

Impact

Exploitation of this vulnerability allows for authenticated SQL injection, where an attacker can execute arbitrary SQL commands. This could lead to unauthorized data access or manipulation within the database.

Remediation

Users are advised to update the CDR module to the latest version. Additionally, access to the FreePBX Administrator Control Panel should be restricted to authorized users, and hostile network access should be denied using the FreePBX Firewall module.

Added: Mar 5, 2026, 7:22 PM
Updated: Mar 5, 2026, 7:44 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
3.1
exploitability
4.9
remediation
7.9
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.