Skip to main content

Vendor archive

nchsoftware CVEs

Beta · best-effort

34 CVEs tagged to vendor nchsoftware0 Critical, 5 High, 29 Medium, 0 Low, 0 Unrated.

CVE-2021-37447

Published Jul 25, 2021

In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37446

Published Jul 25, 2021

In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37445

Published Jul 25, 2021

In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37444

Published Jul 25, 2021

NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathnam…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37443

Published Jul 25, 2021

NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37470

Published Jul 25, 2021

In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary J…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37467

Published Jul 25, 2021

In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37462

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37461

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37460

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37459

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37458

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37457

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37456

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37455

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37454

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37453

Published Jul 25, 2021

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2