CVE-2023-37191: XSS
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this stored cross-site scripting (XSS) vulnerability?
The vulnerability ID for this stored cross-site scripting (XSS) vulnerability is CVE-2023-37191.
What is the severity of CVE-2023-37191?
CVE-2023-37191 has a severity keyword of medium and a severity value of 4.
Which software version is affected by CVE-2023-37191?
Issabel issabel-pbx v.4.0.0-6 is affected by CVE-2023-37191.
How can an attacker exploit the vulnerability?
An attacker can exploit the vulnerability by injecting a crafted payload into the Group and Description parameters.
Are there any references available for CVE-2023-37191?
Yes, you can find references for CVE-2023-37191 at: [https://reference3.example.com/index.php?menu=faxnew](https://reference3.example.com/index.php?menu=faxnew) and [https://github.com/sahiloj/CVE-2023-37191/blob/main/README.md](https://github.com/sahiloj/CVE-2023-37191/blob/main/README.md).