Vulnerabilities > Nchsoftware > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-25 CVE-2021-37456 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37457 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37458 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37459 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37460 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37461 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37462 Cross-site Scripting vulnerability in Nchsoftware Axon PBX
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37463 Cross-site Scripting vulnerability in Nchsoftware Quorum
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37464 Cross-site Scripting vulnerability in Nchsoftware Quorum
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
network
low complexity
nchsoftware CWE-79
5.4
2021-07-25 CVE-2021-37465 Cross-site Scripting vulnerability in Nchsoftware Quorum
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
network
low complexity
nchsoftware CWE-79
5.4