CVE-2023-37596: CSRF
Published Jul 11, 2023
·Updated
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Affected Software
1 affected component
Issabel pbx=4.0.0-6
Event History
Jul 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF vulnerability in issabel-pbx v.4.0.0-6?
The vulnerability ID for this CSRF vulnerability in issabel-pbx v.4.0.0-6 is CVE-2023-37596.
2
What is the severity of CVE-2023-37596?
The severity of CVE-2023-37596 is high with a CVSS score of 8.1.
3
How does this CSRF vulnerability in issabel-pbx v.4.0.0-6 affect the affected software?
This CSRF vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
4
What is the Common Weakness Enumeration (CWE) ID for this CSRF vulnerability in issabel-pbx v.4.0.0-6?
The Common Weakness Enumeration (CWE) ID for this CSRF vulnerability in issabel-pbx v.4.0.0-6 is CWE-352.
5
How can I fix the CSRF vulnerability in issabel-pbx v.4.0.0-6?
To fix the CSRF vulnerability in issabel-pbx v.4.0.0-6, it is recommended to apply the latest security patches or updates provided by the vendor.