CVE-2022-26961
NONE—CVSS v3
—CVSS v2
0.14%
EPSS (exploit probability)
—CWE
Description
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
Affected routers (0)
No routers currently mapped to this CVE in our database.