Stored XSS Vulnerability in Nokia NetAct Affecting Internal Users
CVE-2023-26059
5.4MEDIUM
What is CVE-2023-26059?
A vulnerability has been identified in Nokia NetAct versions prior to 22 SP1037 that enables attackers to exploit Stored XSS via the Site Configuration Tool. Internal users can upload a ZIP file without proper validation, leading to potential execution of malicious scripts. While the application is situated behind a perimeter firewall, the risk arises from internal access, allowing targeted exploitation. It’s crucial for organizations to review their internal user permissions and implement additional input validation to mitigate this vulnerability.