Back to Database
Status published
Medium
CVE-2024-47071
OSS Endpoint Manager allows unauthorized access to read system files
Vulnerability Description
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47071
Credits & Attribution
No credits recorded in the NVD database.
References
More from FreePBX
View All →CVE-2025-67736
Authenticated SQL Injection in FreePBX tts (Text To Speech) module
High
8.6
CVE-2025-67722
Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation
Medium
5.7
CVE-2025-67513
FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API
Medium
6.9
CVE-2025-66039
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
Critical
9.3
CVE-2025-64328
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
High
8.6
Affected Vendor
FreePBX
View all reports →Affected Software
endpointman
Vulnerable Versions:
< 14.0.4
Timeline
Official Publish:
October 1st, 2024
Last Modified:
February 13th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N