FreePBX Backup & Restore — PHP Object Injection to RCE
An authenticated remote code execution vulnerability in the FreePBX Backup & Restore module caused by unsafe deserialization of attacker-controlled manifest data during backup restoration.
- Class
- Unsafe Deserialization
- Impact
- Remote Code Execution
- Access
- Authenticated