Impact
CWE‑79: The vulnerability allows an attacker to inject JavaScript code via the "name" parameter in two Web GUI pages of Italtel NetMatch‑S. When an authenticated user accesses these pages, the injected script executes in the user’s browser without any additional interaction. This stored cross‑site scripting can be abused to steal session cookies, modify page content, or execute further actions on behalf of the victim.
Affected Systems
Italtel NetMatch‑S version 5.0.0‑20200703 is impacted. No other versions are mentioned in the advisory.
Risk and Exploitability
The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.4 indicates a medium severity assessment, but stored XSS typically poses a high risk when authentication is required, since the malicious code runs with the privileges of a legitimate user. An attacker only needs to craft a request containing the "name" parameter and deliver it to a victim who will subsequently load the affected page.
OpenCVE Enrichment