Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.
PoC: lab-cve-2025-57819
FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).
[POC] GHSA-66m8-c62j-h6v5 — CVE-2025-57819
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: CVE-2025-57819-RCE
CVE-2025-57819-RCE_PoC
PoC: CVE-2025-57819-POC
FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行
PoC: htb-connected-writeup
Writeup for HackTheBox Connected — FreePBX CVE-2025-57819 SQLi + incron privesc
PoC: FreePBX-SQLi-RCE
CVE-2025-57819 FreePBX SQLi RCE PoC
PoC: CVE-2025-57819-FreePBX-RCE2Root
CVE-2025-57819 Unauthenticated RCE
PoC: FreePBX-CVE-2025-57819-CVE-2025-61678
Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Manager) to achieve Remote Code Execution (RCE). For educational use only.
PoC: FreePBX-CVE-2025-57819
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
PoC: freepbx-endpoint-sqli-rce
Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.
PoC: CVE-2025-57819-exploit
FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit
PoC: CVE-2025-57819-poc
CVE-2025-57819 poc
PoC: CVE-2025-57819_FreePBX-PoC
🔍 Detect SQL injection risks in FreePBX's admin interface safely and efficiently, providing actionable insights and clean JSON reports for security teams.
PoC: CVE-2025-57819_FreePBX
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.
PoC: CVE-2025-57819_FreePBX-PoC
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
PoC: SQL-Injection-and-RCE_CVE-2025-57819
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
PoC: Blackash-CVE-2025-57819
CVE-2025-57819
PoC: CVE-2025-57819
A write up of CVE-2025-57819, a vulnerability affecting FreePBX 15, 16, and 17
PoC: CVE-2025-57819
FreePBX SQL Injection Exploit
PoC: cve-2025-57819
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
PoC: CVE-2025-57819-ioc-check
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
PoC: CVE-2025-57819
Detection for CVE-2025-57819
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free