Cross-Site Scripting Vulnerability in Nokia NetAct Product
CVE-2023-26061

5.4MEDIUM

Key Information:

Vendor
Nokia
Status
Vendor
CVE Published:
24 April 2023

Summary

An XSS vulnerability exists in Nokia's NetAct product prior to version 22 FP2211, which allows users to create a script through the Scheduled Search tab in the Alarm Reports Dashboard. This is due to a lack of input validation when scheduling tasks, potentially enabling attackers to execute malicious scripts. Although the nature of this vulnerability makes exploitation quite complex, requiring specific dynamically generated parameters, it primarily poses a risk to internal users who have access to the system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.