CVE-2023-34839: CSRF
A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34839?
CVE-2023-34839 has a medium severity rating due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2023-34839?
To fix CVE-2023-34839, update Issabel PBX to version 4.0.0-7 or later, which addresses this vulnerability.
Can CVE-2023-34839 be exploited remotely?
Yes, CVE-2023-34839 can be exploited remotely by attackers to perform unauthorized actions on the Issabel PBX application.
What is a Cross Site Request Forgery (CSRF) vulnerability in the context of CVE-2023-34839?
In the context of CVE-2023-34839, a CSRF vulnerability allows attackers to perform actions on behalf of a user without their consent.
Who is affected by CVE-2023-34839?
Users and administrators of Issabel PBX version 4.0.0-6 are affected by CVE-2023-34839.