Логотип exploitDog
bind:CVE-2023-26059
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-26059

Количество 3

Количество 3

nvd логотип

CVE-2023-26059

почти 3 года назад

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-g87p-p63w-9573

почти 3 года назад

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2023-01305

больше 3 лет назад

Уязвимость инструмента Site Configuration Tool системы управления сетью NetAct, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-26059

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-g87p-p63w-9573

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-01305

Уязвимость инструмента Site Configuration Tool системы управления сетью NetAct, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу