Skip to content
Noroxi

Issabel records

12 published records for vendor issabel.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • Issabel PBX Asterisk-Cli os command injection

    CriticalCVSS 9.8Proof of conceptEPSS 58%

    issabel · pbxJan 28, 2024

  • Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delet

    HighCVSS 8.1Proof of conceptEPSS 1%

    issabel · pbxJul 11, 2023

  • Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted

    HighCVSS 8.1Proof of conceptEPSS 1%

    issabel · pbxJul 11, 2023

  • An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

    HighCVSS 7.5Proof of conceptEPSS 4%

    issabel · pbxJul 13, 2023

  • A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom

    MediumCVSS 6.8Proof of conceptEPSS 1%

    issabel · pbxJun 27, 2023

  • issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability.

    MediumCVSS 6.1No exploitEPSS 1%

    issabel · pbxNov 29, 2021

  • Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web

    MediumCVSS 5.4No exploitEPSS 1%

    issabel · pbxFeb 15, 2022

  • A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit

    MediumCVSS 4.8Proof of conceptEPSS 1%

    issabel · pbxJul 10, 2023

  • A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML

    MediumCVSS 4.8Proof of conceptEPSS 1%

    issabel · pbxJul 10, 2023

  • A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit

    MediumCVSS 4.8No exploitEPSS 1%

    issabel · pbxJul 6, 2021

  • A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML

    MediumCVSS 4.8Proof of conceptEPSS 0%

    issabel · pbxJul 10, 2023

  • A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the del

    MediumCVSS 4.5Proof of conceptEPSS 1%

    issabel · pbxJul 13, 2023