8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Description
## Summary
Authenticated SQL Injection Vulnerability in Endpoint Module Rest API
Authenticated SQL Injection Vulnerability in Endpoint Module Rest API
AI Analysis
Authenticated SQL injection vulnerability in the Endpoint Module Rest API
Basic Information
ID
CVE-2025-62173
Source
GitHub_M
Published
Dec 3, 2025 at 23:14
Affected Product
Vendor
FreePBX
Product
security-reporting
Version
< 16.0.41
Affected Versions
FreePBX security-reporting < 16.0.41
FreePBX security-reporting >= 17.0.0, < 17.0.6
FreePBX security-reporting >= 17.0.0, < 17.0.6
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
FreePBX
Product
Endpoint Module Rest API
Version
< 16.0.41, >= 17.0.0 and < 17.0.6