CVE-2021-37458
Description
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in NCH Axon PBX 2.22 and earlier allows authenticated users to inject arbitrary JavaScript via the primary phone field.
Vulnerability
NCH Axon PBX version 2.22 and earlier is affected by a stored cross-site scripting (XSS) vulnerability. The primary phone field lacks input validation, allowing authenticated users to inject arbitrary JavaScript that is stored on the server and later executed in the browsers of other users viewing the affected configuration panel [1][2].
Exploitation
An attacker must have valid credentials to log into the Axon PBX web control panel. After authentication, the attacker navigates to the user or extension settings and enters a malicious payload into the primary phone field. The injected script is then stored and will execute in the browsers of any administrator or user who views that extension's details page. The attack requires no additional user interaction beyond normal page navigation [2].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the authenticated user's session. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. Because the XSS is stored, it can affect multiple users over time, increasing the potential for data exfiltration or further compromise of the PBX administration console [1][2].
Mitigation
The vendor (NCH Software) has marked Axon PBX as a legacy program that is no longer supported; no security patch has been released. Users should upgrade to a supported alternative or restrict access to the Axon web interface to trusted users only. As of the publication date, no fix is available [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- NCH/Axon PBXdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/0xfml/poc/blob/main/NCH/Axon_2.22_XSS.mdmitrex_refsource_MISC
- www.nch.com.au/pbx/index.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.