CVE-2022-26961

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 21:17

Updated : 2026-09-09 19:17


NVD link : CVE-2022-26961

Mitre link : CVE-2022-26961

CVE.ORG link : CVE-2022-26961


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')