CVE-2025-55209 - CVE House
Back to Database
Status published Medium CVE-2025-55209

FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel

Vulnerability Description

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panel (UCP) user to inject malicious JavaScript into the system. The malicious code executes in the context of an administrator when they interact with the affected component, leading to session hijacking and potential privilege escalation. This issue is fixed in versions 15.0.14, 16.0.27 and 17.0.6.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55209

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

contactmanager
Vulnerable Versions:
< 15.0.14, >= 16.0.0, < 16.0.27, >= 17.0.0, < 17.0.6

Timeline

Official Publish: September 4th, 2025
Last Modified: February 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)