PT-2023-25025 · Issabel · Issabel
Sahil Ojha
·
Published
2023-06-27
·
Updated
2023-07-06
·
CVE-2023-34839
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Issabel issabel-pbx version 4.0.0-6
Description
A Cross Site Request Forgery (CSRF) issue allows a remote attacker to gain privileges by creating a new user function in the application via a custom CSRF exploit.
Recommendations
For Issabel issabel-pbx version 4.0.0-6, consider disabling the user creation function as a temporary workaround until a patch is available. Restrict access to the application to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Issabel