CVE-2022-26961: XSS
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NPIBCF-NATUP-01/NMSCI-WebGui/backuprestore.jsp and NPIBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Authenticated users who browse the affected backup/restore or storage pages can trigger JavaScript that was previously stored through the name parameter. The issue therefore affects users with access to those pages after a malicious payload has been saved.
What does an attacker need to exploit it?
The attacker needs the ability to submit a malicious value through the name parameter on the affected pages. Exploitation relies on a later authenticated user browsing a page that contains the stored payload.