VendorsIssabelpbx4.0.0-6
Vulnerabilities

Issabel PBX 4.0.0-6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-37596
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Published 2023-07-11 · Modified
8.1EPSS 0.006
CVE-2023-37597
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Published 2023-07-11 · Modified
8.1EPSS 0.006
CVE-2023-37599
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
Published 2023-07-13 · Modified
7.5EPSS 0.036
CVE-2023-34839
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.
Published 2023-06-27 · Modified
6.8EPSS 0.007
CVE-2023-37191
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
Published 2023-07-11 · Modified
4.8EPSS 0.006
CVE-2023-37190
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
Published 2023-07-11 · Modified
4.8EPSS 0.005
CVE-2023-37598
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
Published 2023-07-13 · Modified
4.5EPSS 0.006