CVE-2023-37597: CSRF
Published Jul 11, 2023
·Updated
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Affected Software
1 affected component
Issabel pbx=4.0.0-6
Event History
Jul 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-37597?
CVE-2023-37597 is a Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6.
2
How does CVE-2023-37597 affect Issabel PBX?
CVE-2023-37597 affects Issabel PBX v.4.0.0-6.
3
What is the severity of CVE-2023-37597?
CVE-2023-37597 has a severity rating of 8.1 (High).
4
How can a remote attacker exploit CVE-2023-37597?
A remote attacker can exploit CVE-2023-37597 by causing a denial of service via the delete user grouplist function.
5
How can I fix CVE-2023-37597?
To fix CVE-2023-37597, it is recommended to update to a patched version of Issabel PBX or apply any available security patches provided by the vendor.