First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Axon Pbx | <=2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37461 is a vulnerability that allows for Cross Site Scripting (XSS) attacks in NCH Axon PBX v2.22 and earlier versions.
CVE-2021-37461 has a severity rating of medium with a CVSS score of 5.4.
CVE-2021-37461 affects NCH Axon PBX versions 2.22 and earlier, allowing for Cross Site Scripting (XSS) attacks via the '/extensionsinstruction?id=' endpoint.
At the moment, there is no official fix for CVE-2021-37461. It is recommended to follow the vendor's security advisories for updates or patches.
To protect your NCH Axon PBX from CVE-2021-37461, you can implement web application firewall rules to sanitize user input and prevent the execution of malicious scripts.