VYPR
Unrated severityNVD Advisory· Published Oct 21, 2019· Updated Aug 5, 2024

CVE-2019-16964

CVE-2019-16964

Description

app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FusionPBX up to 4.5.7 Call Center Queue Module allows authenticated command injection via cmd parameter, enabling www-data-level command execution.

Vulnerability

The Call Center Queue Module in FusionPBX versions up to and including 4.5.7 contains a command injection vulnerability in app/call_centers/cmd.php. The script accepts a cmd parameter from user input without proper validation or sanitization, allowing an attacker to inject arbitrary commands. The vulnerability stems from the lack of a whitelist or input filtering for the cmd value, as seen in the fix commit [1].

Exploitation

An authenticated attacker with at least the permissions call_center_queue_add or call_center_queue_edit can exploit this by sending a crafted GET request to app/call_centers/cmd.php with a cmd parameter containing malicious commands. The commands are executed via the FreeSwitch event socket interface, running as the www-data user. No additional user interaction is required beyond authentication [2].

Impact

Successful exploitation allows the attacker to execute arbitrary system commands on the host operating system with the privileges of the www-data user. This can lead to full compromise of the FusionPBX server, including data exfiltration, installation of backdoors, or lateral movement within the network. The CVSS score for this vulnerability is 8.8 (HIGH) [2].

Mitigation

The issue was fixed in commit 2f9e591 on August 15, 2019, and included in FusionPBX versions after 4.5.7. Users should upgrade to the latest patched version. No workarounds are available; the fix implements a whitelist of allowed commands (load, unload, reload) and validates the queue parameter as a UUID [1][2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.