SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2022-26962

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability affects Italtel NFV 11.1.2-20210318, specifically within the Java-based web interface, allowing for multiple stored cross-site scripting (XSS) attacks via certain parameters. An attacker could inject arbitrary JavaScript, which would execute whenever an authenticated user accesses the compromised page, potentially leading to session hijacking or data theft. Organizations using this version of Italtel NFV should prioritize remediation to protect their users from these risks.

CVE
CVE-2022-26962
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
Java

Original NVD Description

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.