Description

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panel (UCP) user to inject malicious JavaScript into the system. The malicious code executes in the context of an administrator when they interact with the affected component, leading to session hijacking and potential privilege escalation. This issue is fixed in versions 15.0.14, 16.0.27 and 17.0.6.

INFO

Published Date :

2025-09-04T22:50:59.946Z

Last Modified :

2025-09-05T15:47:36.235Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-55209 vulnerability.

Vendors Products
Freepbx
  • Freepbx
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-55209.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability