CVE-2021-26596: XSS
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26596?
CVE-2021-26596 is a vulnerability in Nokia NetAct 18A that allows a malicious user to upload a file with a manipulated filename and execute JavaScript code on a victim's web browser.
What is the severity of CVE-2021-26596?
The severity of CVE-2021-26596 is medium, with a CVSS score of 5.4.
How does CVE-2021-26596 affect Nokia NetAct?
CVE-2021-26596 affects Nokia NetAct 18A by allowing a malicious user to execute JavaScript code on a victim's web browser through a manipulated filename in an uploaded file.
How can CVE-2021-26596 be exploited?
CVE-2021-26596 can be exploited by uploading a file with a manipulated filename that includes JavaScript code and then tricking a victim into executing that file.
Is there a fix available for CVE-2021-26596?
At the moment, there is no specific fix available for CVE-2021-26596, but it is recommended to apply any patches or updates provided by the vendor to mitigate the risk.