VYPR
Unrated severityNVD Advisory· Published Jul 25, 2021· Updated Aug 4, 2024

CVE-2021-37456

CVE-2021-37456

Description

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in NCH Axon PBX v2.22 and earlier via blacklist IP address allows authenticated attackers to inject arbitrary JavaScript.

Vulnerability

Stored Cross-Site Scripting (XSS) exists in NCH Axon PBX version 2.22 and earlier [1]. The vulnerability resides in the blacklist IP address field, where user-supplied input is not properly sanitized before being stored and later rendered in the administrative web interface [2]. This allows an authenticated user to inject arbitrary JavaScript code that will execute in the context of other administrators' browsers when they view the blacklist page.

Exploitation

An attacker must have valid administrative credentials to access the blacklist configuration page [2]. The attacker can then insert a malicious payload (e.g., ``) into the IP address field. Once saved, the payload is stored and executed whenever another administrator loads the blacklist page, triggering the XSS without further interaction.

Impact

Successful exploitation leads to stored XSS, enabling the attacker to execute arbitrary JavaScript in the context of the victim's session. This can result in session hijacking, credential theft, defacement, or redirection to malicious sites. The attack is persistent and affects all users who view the blacklist page.

Mitigation

NCH Software has marked Axon PBX as a legacy product and no longer provides security updates [1]. As of the publication date, no official patch is available. Users are advised to restrict administrative access to trusted personnel and consider migrating to a supported PBX solution. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NCH/Axon PBXdescription
  • Nch/Axon PBXllm-fuzzy
    Range: <=2.22

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.