Executive brief
FreePBX is an open-source IP PBX (telephone system) used to manage business phone calls and extensions. The Missed Call module contains a SQL injection vulnerability that allows unauthenticated callers to corrupt the database and modify administrator accounts by crafting malicious caller ID information in SIP headers. An attacker could gain unauthorized remote access to the entire FreePBX system, compromising all phone and user management functionality.
Technical details
The vulnerability is an unauthenticated SQL injection flaw in the FreePBX Missed Call module, specifically in the agi-bin/missedcallnotify.php file. The inbound Caller ID name from SIP From headers is inserted directly into a missedcalllog SQL INSERT statement without escaping or using parameterized queries. An unauthenticated attacker can trigger the injection when a monitored extension goes unanswered by crafting a malicious Caller ID name in the SIP message. The attacker can execute arbitrary SQL commands to corrupt the database and modify FreePBX administrator account credentials. The vulnerability affects versions 16.0.0 through 16.0.11 and 17.0.4, with patches available in 16.0.11 and 17.0.4.
Affected products
- FreePBX Missed Call Module 16.0.0 to 16.0.10, 17.0.0 to 17.0.3
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: Versions 16.0.11 and 17.0.4 include fix