PT-2023-13729 · Italtel · Italtel Netmatch-S Ci

Fabio Romano

+3

·

Published

2023-01-27

·

Updated

2025-03-28

·

CVE-2022-39813

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Italtel NetMatch-S CI version 5.2.0-20211008
Description The issue allows for Multiple Reflected/Stored XSS, enabling an attacker to inject arbitrary JavaScript. This can be achieved via the "j security check" endpoint under NMSCIWebGui, using the j username parameter, or via the "actloglineview.jsp" endpoint under NMSCIWebGui, using the name or actLine parameters. The injected payload would be triggered every time an authenticated user browses the page containing it.
Recommendations For Italtel NetMatch-S CI version 5.2.0-20211008, consider restricting access to the "j security check" and "actloglineview.jsp" endpoints under NMSCIWebGui until a patch is available. As a temporary workaround, avoid using the j username, name, and actLine parameters in the affected endpoints to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39813

Affected Products

Italtel Netmatch-S Ci