Vulnerabilities > Freepbx > Disa

DATE CVE VULNERABILITY TITLE RISK
2019-06-20 CVE-2018-15892 SQL Injection vulnerability in Freepbx Disa
FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.
network
freepbx CWE-89
6.0