CVE-2023-37598: CSRF
Published Jul 13, 2023
·Updated
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
Affected Software
1 affected component
Issabel pbx=4.0.0-6
Event History
Jul 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
09:15 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37598?
CVE-2023-37598 has been classified as a moderate severity Cross Site Request Forgery vulnerability.
2
How do I fix CVE-2023-37598?
To fix CVE-2023-37598, update to the latest version of Issabel PBX that addresses this CSRF vulnerability.
3
What type of vulnerability is CVE-2023-37598?
CVE-2023-37598 is a Cross Site Request Forgery (CSRF) vulnerability.
4
What can attackers do with CVE-2023-37598?
Attackers exploiting CVE-2023-37598 can cause denial of service by invoking the delete new virtual fax function.
5
Which version of Issabel PBX is affected by CVE-2023-37598?
Issabel PBX version 4.0.0-6 is the affected version in CVE-2023-37598.