| Summary | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5. |
|---|---|
| Publication Date | May 29, 2026, 11:16 p.m. |
| Registration Date | May 30, 2026, 4:14 a.m. |
| Last Update | May 30, 2026, 12:06 a.m. |