CVE-2021-37457
Description
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in NCH Axon PBX v2.22 and earlier via the SipRule field allows authenticated attackers to inject arbitrary JavaScript.
Vulnerability
A stored Cross-Site Scripting (XSS) vulnerability exists in NCH Axon PBX version 2.22 and earlier. The SipRule field lacks proper input validation, allowing an authenticated user to inject arbitrary JavaScript code that is stored and later executed in the browsers of other users who view the affected page [2].
Exploitation
An attacker must have authenticated access to the Axon PBX web control panel. The attacker navigates to the SIP rule configuration, inserts a malicious payload into the SipRule field, and saves the rule. When any other user (including administrators) views the SIP rules, the injected script executes in their browser context [2].
Impact
Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking, theft of sensitive data (e.g., credentials, call logs), or further compromise of the PBX system through actions performed on behalf of the victim [2].
Mitigation
NCH Software has marked Axon PBX as a legacy product and no longer provides security updates [1]. No patch is available. Organizations still using this software should restrict access to the web control panel to trusted users only and consider migrating to a supported alternative [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- NCH/Axon PBXdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/0xfml/poc/blob/main/NCH/Axon_2.22_XSS.mdmitrex_refsource_MISC
- www.nch.com.au/pbx/index.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.