CNNVD-202510-067 Information

CNNVD ID

CNNVD-202510-067

CVE-2025-40647

  • CNNVD Published: 2025-10-01

Description (Chinese)

IssabelPbx是Issabel基金会的一个开源 Gui(图形用户界面)。用于控制和管理 Asterisk (Pbx)。 IssabelPbx 5.0.0版本存在跨站脚本漏洞,该漏洞源于对index.php中email参数的用户输入验证不足,可能导致存储型跨站脚本攻击。

Description (English)

IssabelPbx is an open source of the Issabel Foundation Gui (a graphical user interface). For control and management of Asterisk (Pbx). IssabelPbx version 5.0.0 has a cross-site script loophole, which results from inadequate user input validation of email parameters in index.php, which may result in storage-type cross-site script attacks.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Issabel

Published

2025-10-01

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-issabel-products

Patch

https://www.issabel.com/

Share on: