CVE-2024-28803: XSS
Published Mar 13, 2025
·Updated
Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter
Affected Software
2 affected components
Italtel i-MCS NFV
Italtel i-MCS NFV=12.1.0-20211215
Event History
Mar 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28803?
CVE-2024-28803 has been classified with a medium severity due to its potential impact on users through cross-site scripting.
2
How do I fix CVE-2024-28803?
To fix CVE-2024-28803, validate and sanitize all user inputs to prevent the injection of arbitrary scripts.
3
Who is affected by CVE-2024-28803?
CVE-2024-28803 affects users of Italtel S.p.A. i-MCS NFV version 12.1.0-20211215.
4
What type of attack does CVE-2024-28803 facilitate?
CVE-2024-28803 facilitates cross-site scripting (XSS) attacks, allowing remote attackers to inject malicious scripts into web pages.
5
Is authentication required to exploit CVE-2024-28803?
No, CVE-2024-28803 can be exploited by unauthenticated remote attackers.