First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Axon Pbx | <=2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37455 is a vulnerability identified as Cross Site Scripting (XSS) in NCH Axon PBX v2.22 and earlier.
CVE-2021-37455 affects NCH Axon PBX v2.22 and earlier versions through a Cross Site Scripting (XSS) vulnerability in the outbound dialing plan.
The severity of CVE-2021-37455 is medium with a CVSS score of 5.4.
At the moment, there is no official fix available for CVE-2021-37455. It is recommended to stay updated with the latest version of NCH Axon PBX and follow best security practices.
More information about CVE-2021-37455 can be found in the official NCH Axon PBX website and the associated GitHub link provided in the references section.