Security Vulnerabilities
- CVEs Published In July 2021
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).