First published: Thu Mar 25 2021(Updated: )
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia NetAct | =18a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26596 is a vulnerability in Nokia NetAct 18A that allows a malicious user to upload a file with a manipulated filename and execute JavaScript code on a victim's web browser.
The severity of CVE-2021-26596 is medium, with a CVSS score of 5.4.
CVE-2021-26596 affects Nokia NetAct 18A by allowing a malicious user to execute JavaScript code on a victim's web browser through a manipulated filename in an uploaded file.
CVE-2021-26596 can be exploited by uploading a file with a manipulated filename that includes JavaScript code and then tricking a victim into executing that file.
At the moment, there is no specific fix available for CVE-2021-26596, but it is recommended to apply any patches or updates provided by the vendor to mitigate the risk.