CVE-2023-0480: Vitalpbx
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the application is vulnerable to CSRF.
Affected products
- Vitalpbx Vitalpbx: version 3.2.3 only
Published 2023-04-04. Last modified 2026-06-17.