Issabel
Issabel PBX: vulnerabilidades y CVE
Issabel PBX tiene 13 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89026 | Crítica (9.3) | 0.69% | — | 15 sept 2026 | The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation,… |
| CVE-2024-0986 | Crítica (9.8) | 58% | — | 29 ene 2024 | A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the… |
| CVE-2023-37599 | Alta (7.5) | 3.6% | — | 13 jul 2023 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory |
| CVE-2023-37598 | Media (4.5) | 0.57% | — | 13 jul 2023 | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function. |
| CVE-2023-37597 | Alta (8.1) | 0.62% | — | 11 jul 2023 | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function. |
| CVE-2023-37596 | Alta (8.1) | 0.62% | — | 11 jul 2023 | Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function. |
| CVE-2023-37190 | Media (4.8) | 0.48% | — | 11 jul 2023 | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name… |
| CVE-2023-37189 | Media (4.8) | 0.73% | — | 11 jul 2023 | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix… |
| CVE-2023-37191 | Media (4.8) | 0.65% | — | 11 jul 2023 | A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters. |
| CVE-2023-34839 | Media (6.8) | 0.66% | — | 27 jun 2023 | A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application. |
| CVE-2021-46558 | Media (5.4) | 0.56% | — | 15 feb 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password… |
| CVE-2021-43695 | Media (6.1) | 0.57% | — | 29 nov 2021 | issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain… |
| CVE-2021-34190 | Media (4.8) | 0.64% | — | 6 jul 2021 | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Name" or… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.