VendorsNCHaxon_pbxall versions
Vulnerabilities

NCH Software Axon PBX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-11551
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.
Published 2018-06-01 · Modified
9.3EPSS 0.025
CVE-2021-37441
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
Published 2021-07-25 · Modified
8.8EPSS 0.015
CVE-2021-37440
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
Published 2021-07-25 · Modified
6.5EPSS 0.012
CVE-2018-11552
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
Published 2018-06-01 · Modified
6.1EPSS 0.286