Issabel kayıtları
issabel üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2024-0986Kavram kanıtı | Issabel PBX Asterisk-Cli os command injectionissabel · pbx · CWE-78 | Kritik9,8 | — | %58,2 | 28 Oca 2024 |
32İzleyin | CVE-2023-37597Kavram kanıtı | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the deletissabel · pbx · CWE-352 | Yüksek8,1 | — | %0,6 | 11 Tem 2023 |
32İzleyin | CVE-2023-37596Kavram kanıtı | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a craftedissabel · pbx · CWE-352 | Yüksek8,1 | — | %0,6 | 11 Tem 2023 |
31İzleyin | CVE-2023-37599Kavram kanıtı | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directoryissabel · pbx · CWE-668 | Yüksek7,5 | — | %3,6 | 13 Tem 2023 |
27İzleyin | CVE-2023-34839Kavram kanıtı | A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom issabel · pbx · CWE-352 | Orta6,8 | — | %0,7 | 27 Haz 2023 |
24İzleyin | CVE-2021-43695İstismar yok | issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability.issabel · pbx · CWE-79 | Orta6,1 | — | %0,6 | 29 Kas 2021 |
21İzleyin | CVE-2021-46558İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary webissabel · pbx · CWE-79 | Orta5,4 | — | %0,6 | 15 Şub 2022 |
19İzleyin | CVE-2023-37189Kavram kanıtı | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitissabel · pbx · CWE-79 | Orta4,8 | — | %0,7 | 10 Tem 2023 |
19İzleyin | CVE-2023-37191Kavram kanıtı | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTMLissabel · pbx · CWE-79 | Orta4,8 | — | %0,6 | 10 Tem 2023 |
19İzleyin | CVE-2021-34190İstismar yok | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitissabel · pbx · CWE-79 | Orta4,8 | — | %0,6 | 6 Tem 2021 |
19İzleyin | CVE-2023-37190Kavram kanıtı | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTMLissabel · pbx · CWE-79 | Orta4,8 | — | %0,5 | 10 Tem 2023 |
18İzleyin | CVE-2023-37598Kavram kanıtı | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delissabel · pbx · CWE-352 | Orta4,5 | — | %0,6 | 13 Tem 2023 |
- CVE-2024-098656Planlayın
Issabel PBX Asterisk-Cli os command injection
KritikCVSS 9,8Kavram kanıtıEPSS %58issabel · pbx28 Oca 2024
- CVE-2023-3759732İzleyin
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delet
YüksekCVSS 8,1Kavram kanıtıEPSS %1issabel · pbx11 Tem 2023
- CVE-2023-3759632İzleyin
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted
YüksekCVSS 8,1Kavram kanıtıEPSS %1issabel · pbx11 Tem 2023
- CVE-2023-3759931İzleyin
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
YüksekCVSS 7,5Kavram kanıtıEPSS %4issabel · pbx13 Tem 2023
- CVE-2023-3483927İzleyin
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom
OrtaCVSS 6,8Kavram kanıtıEPSS %1issabel · pbx27 Haz 2023
- CVE-2021-4369524İzleyin
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1issabel · pbx29 Kas 2021
- CVE-2021-4655821İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web
OrtaCVSS 5,4İstismar yokEPSS %1issabel · pbx15 Şub 2022
- CVE-2023-3718919İzleyin
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit
OrtaCVSS 4,8Kavram kanıtıEPSS %1issabel · pbx10 Tem 2023
- CVE-2023-3719119İzleyin
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML
OrtaCVSS 4,8Kavram kanıtıEPSS %1issabel · pbx10 Tem 2023
- CVE-2021-3419019İzleyin
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit
OrtaCVSS 4,8İstismar yokEPSS %1issabel · pbx6 Tem 2021
- CVE-2023-3719019İzleyin
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML
OrtaCVSS 4,8Kavram kanıtıEPSS %0issabel · pbx10 Tem 2023
- CVE-2023-3759818İzleyin
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the del
OrtaCVSS 4,5Kavram kanıtıEPSS %1issabel · pbx13 Tem 2023