Lucene search

K
cveMitreCVE-2023-26061
HistoryApr 24, 2023 - 5:15 p.m.

CVE-2023-26061

2023-04-2417:15:10
CWE-79
mitre
web.nvd.nist.gov
16
nokia netact
cve-2023-26061
xss
input validation
alarm reports
dashboard
security issue

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

40.5%

An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a scheduled task. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.

Affected configurations

Nvd
Node
nokianetactRange20.1
VendorProductVersionCPE
nokianetact*cpe:2.3:a:nokia:netact:*:*:*:*:*:*:*:*

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

40.5%

Related for CVE-2023-26061