Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-0986

Disclosure Date: January 29, 2024 (last updated February 03, 2024)
A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-37599

Disclosure Date: July 13, 2023 (last updated February 25, 2025)
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
Attacker Value
Unknown

CVE-2023-37598

Disclosure Date: July 13, 2023 (last updated February 25, 2025)
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
Attacker Value
Unknown

CVE-2023-37597

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Attacker Value
Unknown

CVE-2023-37596

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Attacker Value
Unknown

CVE-2023-37190

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
Attacker Value
Unknown

CVE-2023-37191

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
Attacker Value
Unknown

CVE-2023-34839

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.