Arbitrary File Upload Vulnerability in Nokia IMPACT Platform
CVE-2021-35483
4.1MEDIUM
What is CVE-2021-35483?
The Applications component of the Nokia IMPACT platform allows authenticated users to upload JavaScript files through the fileupload parameter. This vulnerability occurs when users add or edit existing applications. If an authenticated user accesses the page where the malicious JavaScript is hosted, it executes, potentially compromising the integrity and security of the application and the data it handles.