CVE-2023-37190: XSS
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37190?
CVE-2023-37190 is a stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6.
How does CVE-2023-37190 work?
Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the Virtual Fax Name and Caller ID Name parameters.
What is the severity of CVE-2023-37190?
The severity of CVE-2023-37190 is medium (4 out of 10).
How can I fix CVE-2023-37190?
Update Issabel issabel-pbx to version 4.0.0-7 or later to mitigate the vulnerability.
Where can I find more information about CVE-2023-37190?
You can find more information about CVE-2023-37190 at the following references: [Reference 1](https://reference2.example.com/index.php?menu=grouplist) and [Reference 2](https://github.com/sahiloj/CVE-2023-37190/blob/main/README.md).