Junglewise Threat Intelligence

CVE-2024-36697: Allworx System Software XSS in Admin Login page

CVE-2024-36697 · Severity: medium · CVSS 6.1 · Published 2025-07-10

Executive brief

Allworx System Software, which is used to manage business communication and VoIP systems, contains a security flaw in its administrative login portal. An attacker could trick an administrator into clicking a malicious link, allowing the attacker to run unauthorized scripts in the administrator's web browser. This could lead to the theft of login credentials or unauthorized access to the system's management interface.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Allworx System Software version 9.1.9.12. The flaw is located within the 'query.asp' component of the Admin login portal, specifically due to improper neutralization of the 'SessionID' query parameter. An unauthenticated remote attacker can exploit this by inducing a user (typically an administrator) to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript or HTML in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions.

Affected products

  • Allworx System Software 9.1.9.12

Timeline

  • 2025-07-10: disclosed
  • 2025-07-10: advisory

References