CVE-2026-28284 | FreePBX up to 16.0.9/17.0.4 Logfile sql injection (GHSA-4887-4jwp-327g)
A vulnerability was found in FreePBX up to 16.0.9/17.0.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Logfile Module. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-28284. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.