JavaScript Injection Vulnerability in Nokia NetAct via Site Configuration Tool
CVE-2022-28865
5.4MEDIUM
Summary
A vulnerability in Nokia NetAct 22 through its Site Configuration Tool allows a malicious user to alter an uploaded file's name to inject malicious JavaScript code. This code can then be executed in the victim's web browser, often delivered via a URL parameter that is made publicly available or shared through direct email. The affected parameter is /netact/sct, which poses a significant security risk as it enables potential exploitation of users who visit the manipulated link.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved