CVE-2023-37189: XSS
A stored cross site scripting (XSS) vulnerability in index.php?menu=billingrates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37189?
CVE-2023-37189 is a stored cross site scripting (XSS) vulnerability in Issabel PBX version 4, which allows attackers to execute arbitrary web scripts or HTML.
How does CVE-2023-37189 affect Issabel PBX?
CVE-2023-37189 affects Issabel PBX version 4 and allows attackers to execute arbitrary web scripts or HTML.
What is the severity of CVE-2023-37189?
CVE-2023-37189 has a severity level of medium.
How can I fix CVE-2023-37189 on my Issabel PBX?
To fix CVE-2023-37189 on your Issabel PBX, update to a patched version of the software.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-37189?
CVE-2023-37189 is associated with CWE-79, which is a weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').