CVE-2023-37599: High severity Issabel pbx vulnerability
Published Jul 13, 2023
·Updated
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
Affected Software
1 affected component
Issabel pbx=4.0.0-6
Event History
Jul 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
10:15 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37599?
CVE-2023-37599 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-37599?
To fix CVE-2023-37599, upgrade Issabel PBX to version 4.0.0-7 or later.
3
What type of attack can exploit CVE-2023-37599?
CVE-2023-37599 can be exploited by a remote attacker to obtain sensitive information.
4
What software is affected by CVE-2023-37599?
CVE-2023-37599 affects Issabel PBX version 4.0.0-6.
5
What can be done to mitigate CVE-2023-37599?
Mitigation of CVE-2023-37599 involves securing the modules directory and applying the available patch.