Impact
Italtel NFV 11.1.2-20210318 contains a flaw that allows attackers to store malicious JavaScript in the name, username, or mrfAnnouncementName parameters of the configuration.jsp page. When an authenticated user later visits the page, the injected script executes in that user's browser. This stored cross‑site scripting enables the attacker to steal session cookies, deface content, or perform other client‑side actions that privilege the authenticated user.
Affected Systems
Vulnerable systems include Italtel NFV version 11.1.2-20210318. The flaw resides in the NP_BCCAS-RMCTRL-01/IMCSCIWebGui/web part of the product. Only installations running that build or earlier are affected; later releases may have fixed the issue.
Risk and Exploitability
Because the vulnerability requires an attacker to first gain authenticated access to the web interface, the attack surface is limited to insiders or compromised accounts. No public exploits are known and the EPSS score is not available. Nevertheless, the stored XSS can be leveraged to exfiltrate credentials or inject malicious code during normal operation, presenting a moderate to high risk for affected deployments.
OpenCVE Enrichment