CVE-2026-105269: Satel Netco Design Cross-site Scripting
Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Satel Netco Designto a version that resolves this vulnerability.Fixed in 2.1.7
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated user with Network Operator privileges can exploit it by storing untrusted content in the application.
Who is exposed to the malicious script?
Another user is exposed when they view the affected stored content, at which point the script can execute in that user's browser.
Which versions are affected?
Satel Netco Design versions before v2.1.7 are affected. Upgrading to v2.1.7 or later addresses the affected version range described.