Issabel records
12 published records for vendor issabel.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2024-0986Proof of concept | Issabel PBX Asterisk-Cli os command injectionissabel · pbx · CWE-78 | Critical9.8 | — | 58.2% | Jan 28, 2024 |
32Monitor | CVE-2023-37597Proof of concept | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the deletissabel · pbx · CWE-352 | High8.1 | — | 0.6% | Jul 11, 2023 |
32Monitor | CVE-2023-37596Proof of concept | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a craftedissabel · pbx · CWE-352 | High8.1 | — | 0.6% | Jul 11, 2023 |
31Monitor | CVE-2023-37599Proof of concept | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directoryissabel · pbx · CWE-668 | High7.5 | — | 3.6% | Jul 13, 2023 |
27Monitor | CVE-2023-34839Proof of concept | A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom issabel · pbx · CWE-352 | Medium6.8 | — | 0.7% | Jun 27, 2023 |
24Monitor | CVE-2021-43695No exploit | issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability.issabel · pbx · CWE-79 | Medium6.1 | — | 0.6% | Nov 29, 2021 |
21Monitor | CVE-2021-46558No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary webissabel · pbx · CWE-79 | Medium5.4 | — | 0.6% | Feb 15, 2022 |
19Monitor | CVE-2023-37189Proof of concept | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitissabel · pbx · CWE-79 | Medium4.8 | — | 0.7% | Jul 10, 2023 |
19Monitor | CVE-2023-37191Proof of concept | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTMLissabel · pbx · CWE-79 | Medium4.8 | — | 0.6% | Jul 10, 2023 |
19Monitor | CVE-2021-34190No exploit | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitissabel · pbx · CWE-79 | Medium4.8 | — | 0.6% | Jul 6, 2021 |
19Monitor | CVE-2023-37190Proof of concept | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTMLissabel · pbx · CWE-79 | Medium4.8 | — | 0.5% | Jul 10, 2023 |
18Monitor | CVE-2023-37598Proof of concept | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delissabel · pbx · CWE-352 | Medium4.5 | — | 0.6% | Jul 13, 2023 |
- CVE-2024-098656Plan
Issabel PBX Asterisk-Cli os command injection
CriticalCVSS 9.8Proof of conceptEPSS 58%issabel · pbxJan 28, 2024
- CVE-2023-3759732Monitor
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delet
HighCVSS 8.1Proof of conceptEPSS 1%issabel · pbxJul 11, 2023
- CVE-2023-3759632Monitor
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted
HighCVSS 8.1Proof of conceptEPSS 1%issabel · pbxJul 11, 2023
- CVE-2023-3759931Monitor
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
HighCVSS 7.5Proof of conceptEPSS 4%issabel · pbxJul 13, 2023
- CVE-2023-3483927Monitor
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom
MediumCVSS 6.8Proof of conceptEPSS 1%issabel · pbxJun 27, 2023
- CVE-2021-4369524Monitor
issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability.
MediumCVSS 6.1No exploitEPSS 1%issabel · pbxNov 29, 2021
- CVE-2021-4655821Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web
MediumCVSS 5.4No exploitEPSS 1%issabel · pbxFeb 15, 2022
- CVE-2023-3718919Monitor
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit
MediumCVSS 4.8Proof of conceptEPSS 1%issabel · pbxJul 10, 2023
- CVE-2023-3719119Monitor
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML
MediumCVSS 4.8Proof of conceptEPSS 1%issabel · pbxJul 10, 2023
- CVE-2021-3419019Monitor
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbit
MediumCVSS 4.8No exploitEPSS 1%issabel · pbxJul 6, 2021
- CVE-2023-3719019Monitor
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML
MediumCVSS 4.8Proof of conceptEPSS 0%issabel · pbxJul 10, 2023
- CVE-2023-3759818Monitor
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the del
MediumCVSS 4.5Proof of conceptEPSS 1%issabel · pbxJul 13, 2023