SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2022-26961

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects Italtel NetMatch-S 5.0.0-20200703, specifically in the backup_restore.jsp and storage.jsp pages, where multiple stored cross-site scripting (XSS) vulnerabilities exist due to improper handling of the name parameter. An attacker could exploit this flaw to inject arbitrary JavaScript, which would execute whenever an authenticated user accesses the affected pages, potentially leading to session hijacking or data theft. Organizations using this version of Italtel NetMatch-S should prioritize remediation to protect their users from potential exploitation.

CVE
CVE-2022-26961
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Java

Original NVD Description

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.