VYPR
Unrated severityNVD Advisory· Published Jul 25, 2021· Updated Aug 4, 2024

CVE-2021-37457

CVE-2021-37457

Description

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in NCH Axon PBX v2.22 and earlier via the SipRule field allows authenticated attackers to inject arbitrary JavaScript.

Vulnerability

A stored Cross-Site Scripting (XSS) vulnerability exists in NCH Axon PBX version 2.22 and earlier. The SipRule field lacks proper input validation, allowing an authenticated user to inject arbitrary JavaScript code that is stored and later executed in the browsers of other users who view the affected page [2].

Exploitation

An attacker must have authenticated access to the Axon PBX web control panel. The attacker navigates to the SIP rule configuration, inserts a malicious payload into the SipRule field, and saves the rule. When any other user (including administrators) views the SIP rules, the injected script executes in their browser context [2].

Impact

Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking, theft of sensitive data (e.g., credentials, call logs), or further compromise of the PBX system through actions performed on behalf of the victim [2].

Mitigation

NCH Software has marked Axon PBX as a legacy product and no longer provides security updates [1]. No patch is available. Organizations still using this software should restrict access to the web control panel to trusted users only and consider migrating to a supported alternative [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NCH/Axon PBXdescription
  • Nch/Axon PBXllm-fuzzy
    Range: <=2.22

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.