PT-2026-86255 · Undefined · Undefined

CVE-2022-26961

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP IBCF-NATUP-01/NMSCI-WebGui/backup restore.jsp and NP IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26961

Affected Products

Undefined