CVE-2021-46558: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46558?
CVE-2021-46558 is classified as a high-severity vulnerability due to its potential for leading to arbitrary web script execution.
How does CVE-2021-46558 allow attackers to exploit the system?
CVE-2021-46558 allows attackers to exploit the system by injecting crafted payloads into the username and password fields, resulting in cross-site scripting.
What software versions are affected by CVE-2021-46558?
CVE-2021-46558 specifically affects Issabel PBX version 20200102.
How can I mitigate the risks associated with CVE-2021-46558?
To mitigate the risks of CVE-2021-46558, it is important to sanitize user input and use output encoding to prevent XSS attacks.
Is there a patch available for CVE-2021-46558?
As of now, there is no official patch released for CVE-2021-46558, so it is recommended to apply security best practices to mitigate the vulnerability.