Cross-Site Scripting Vulnerability in Nokia NetAct Product
CVE-2023-26061
5.4MEDIUM
Summary
An XSS vulnerability exists in Nokia's NetAct product prior to version 22 FP2211, which allows users to create a script through the Scheduled Search tab in the Alarm Reports Dashboard. This is due to a lack of input validation when scheduling tasks, potentially enabling attackers to execute malicious scripts. Although the nature of this vulnerability makes exploitation quite complex, requiring specific dynamically generated parameters, it primarily poses a risk to internal users who have access to the system.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved