JavaScript Injection Vulnerability in Nokia NetAct via Site Configuration Tool
CVE-2022-28865
5.4MEDIUM
What is CVE-2022-28865?
A vulnerability in Nokia NetAct 22 through its Site Configuration Tool allows a malicious user to alter an uploaded file's name to inject malicious JavaScript code. This code can then be executed in the victim's web browser, often delivered via a URL parameter that is made publicly available or shared through direct email. The affected parameter is /netact/sct, which poses a significant security risk as it enables potential exploitation of users who visit the manipulated link.