CVE-2019-19538
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
Date published : 2020-03-16
https://wiki.freepbx.org/display/FOP/2019-12-03+Remote+Command+Execution
https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-00