First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Axon Pbx | <=2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37460 is a vulnerability in NCH Axon PBX v2.22 and earlier that allows for Cross-Site Scripting (XSS) attacks via the /planprop?id= parameter.
CVE-2021-37460 has a severity keyword of 'medium' and a severity value of 5.4.
CVE-2021-37460 affects NCH Axon PBX v2.22 and earlier versions.
An attacker can exploit CVE-2021-37460 by injecting and executing malicious script code through the reflected /planprop?id= parameter.
At the moment, there is no specific patch or fix available for CVE-2021-37460. It is recommended to follow the vendor's website for updates and security advisories.