Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-0986
Disclosure Date: January 29, 2024 (last updated February 03, 2024)
A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-37599
Disclosure Date: July 13, 2023 (last updated February 25, 2025)
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
0
Attacker Value
Unknown
CVE-2023-37598
Disclosure Date: July 13, 2023 (last updated February 25, 2025)
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
0
Attacker Value
Unknown
CVE-2023-37597
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
0
Attacker Value
Unknown
CVE-2023-37596
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
0
Attacker Value
Unknown
CVE-2023-37190
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
0
Attacker Value
Unknown
CVE-2023-37189
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.
0
Attacker Value
Unknown
CVE-2023-37191
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
0
Attacker Value
Unknown
CVE-2023-34839
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.
0
Attacker Value
Unknown
CVE-2021-46558
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password fields.
0