CVE-2022-26962: XSS

Published Sep 10, 2026
·
Updated

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NPBCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

Affected Software

1 affected component
Italtel NFV=11.1.2-20210318

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate the Multiple Stored XSS (injecting arbitrary JavaScript) in Italtel NFV by preventing or restricting authenticated access to the affected page/function: NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS (e.g., restrict access to this UI endpoint so fewer users can trigger stored payloads).

Event History

Sep 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

Who is exposed to the stored script payload?

Authenticated users who browse the page containing the malicious announcement are exposed, because the injected JavaScript is triggered whenever they view that page.

2

What does an attacker need to exploit this issue?

The attacker needs the ability to submit a malicious value through the affected announcement fields: name, username, or mrfAnnouncementName. The provided information does not state whether authentication or a particular role is required to create or modify these values.

3

Which component and endpoint should be investigated?

Review the NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp endpoint when used with opration=list and object=announcementAS. Inspect stored announcement data, especially the name, username, and mrfAnnouncementName values, for unexpected script content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203