Reflected XSS Vulnerability in NOKIA NFM-T R19.9
CVE-2022-43675
6.1MEDIUM
Summary
An issue has been identified in NOKIA NFM-T R19.9 that allows for reflected cross-site scripting (XSS) attacks. This vulnerability is exploitable through various parameters within the Network Element Manager, specifically via the filename parameter in the /oms1350/pages/otn/cpbLogDisplay endpoint. Additionally, vulnerabilities exist in the /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay endpoint through the id parameter and across all parameters in /oms1350/pages/otn/mainOtn. Attackers can leverage these weaknesses to execute malicious scripts in the context of an unsuspecting user’s browser, potentially compromising security and privacy.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved