CyberRota Analysis
AI-GeneratedThe vulnerability affects Italtel NFV 11.1.2-20210318, specifically within the Java-based web interface, allowing for multiple stored cross-site scripting (XSS) attacks via certain parameters. An attacker could inject arbitrary JavaScript, which would execute whenever an authenticated user accesses the compromised page, potentially leading to session hijacking or data theft. Organizations using this version of Italtel NFV should prioritize remediation to protect their users from these risks.
Original NVD Description
Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.