Reflected XSS Vulnerability in NOKIA NFM-T R19.9
CVE-2022-43675
6.1MEDIUM
What is CVE-2022-43675?
An issue has been identified in NOKIA NFM-T R19.9 that allows for reflected cross-site scripting (XSS) attacks. This vulnerability is exploitable through various parameters within the Network Element Manager, specifically via the filename parameter in the /oms1350/pages/otn/cpbLogDisplay endpoint. Additionally, vulnerabilities exist in the /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay endpoint through the id parameter and across all parameters in /oms1350/pages/otn/mainOtn. Attackers can leverage these weaknesses to execute malicious scripts in the context of an unsuspecting user’s browser, potentially compromising security and privacy.