VendorsIssabelpbxall versions
Vulnerabilities

Issabel PBX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-0986
Issabel PBX Asterisk-Cli os command injection
Published 2024-01-28 · Modified
9.8EPSS 0.582
CVE-2023-37596
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Published 2023-07-11 · Modified
8.1EPSS 0.006
CVE-2023-37597
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Published 2023-07-11 · Modified
8.1EPSS 0.006
CVE-2023-37599
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
Published 2023-07-13 · Modified
7.5EPSS 0.036
CVE-2023-34839
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.
Published 2023-06-27 · Modified
6.8EPSS 0.007
CVE-2021-43695
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.
Published 2021-11-29 · Modified
6.1EPSS 0.006
CVE-2021-46558
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password fields.
Published 2022-02-15 · Modified
5.4EPSS 0.006
CVE-2023-37189
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.
Published 2023-07-11 · Modified
4.8EPSS 0.007
CVE-2023-37191
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
Published 2023-07-11 · Modified
4.8EPSS 0.006
CVE-2021-34190
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Name" or "Prefix" fields under the "Create New Rate" module.
Published 2021-07-06 · Modified
4.8EPSS 0.006
CVE-2023-37190
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
Published 2023-07-11 · Modified
4.8EPSS 0.005
CVE-2023-37598
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
Published 2023-07-13 · Modified
4.5EPSS 0.006