Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and previous versions via /ipblacklist?errorip= (reflected).
nchsoftware axon pbx