Impact
NSP is vulnerable to a stored cross‑site scripting flaw caused by insufficient validation or encoding of user‑controlled input in its workflow application. An attacker who is authenticated and has permission to use the workflow can embed malicious JavaScript that will execute in the browsers of other users when they view the compromised content. The flaw is a classic example of CWE‑79, where input is reflected into a web page without neutralization, potentially allowing attackers to steal cookies, deface the interface, or relay phishing content.
Affected Systems
Nokia NSP is the affected product. No specific version range is supplied, so all deployments of NSP that include the workflow application may be susceptible until a vendor‑supplied fix is applied.
Risk and Exploitability
The CVSS score is 5.4, EPSS < 1%, and it is not listed in the CISA KEV catalog. Because the flaw requires authentication within the workflow application, the risk depends on the privilege level of users who have write access. Once in effect, the embedded script runs in the context of the victim’s browser, enabling theft of session data or unauthorized actions. With no publicly known exploitation tools, the likelihood is uncertain, but the high potential impact warrants prompt remediation.
OpenCVE Enrichment