Based on what I read of the exploit - it does not apply to 2.8.
Furthermore, it applies only if you have port 80/443 available from the outside.
However Elastix 2.5 beta comes with Freepbx 2.11 and is affected. I would assume that the developers would probably have seen this exploit and will probably make the change before 2.5 goes stable. Again it is mainly important if you expose your ports to the outside.
But an exploit is an exploit and should always be corrected, whether you expose the ports or not.
Regards
Bob