CVE-2021-35483: XSS
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35483?
CVE-2021-35483 has a medium severity rating due to its potential for authenticated users to upload arbitrary JavaScript files.
How do I fix CVE-2021-35483?
To mitigate CVE-2021-35483, ensure to restrict file uploads to only allowable file types and sanitize inputs provided by users.
What version of Nokia IMPACT is affected by CVE-2021-35483?
CVE-2021-35483 affects Nokia IMPACT versions up to and including 19.11.2.10-20210118042150283.
Who can exploit CVE-2021-35483?
CVE-2021-35483 can be exploited by authenticated users who have access to the application upload functionalities.
What is the impact of CVE-2021-35483?
The impact of CVE-2021-35483 includes the risk of XSS attacks due to the arbitrary upload of JavaScript files.