Vulnerability Description: Improper Neutralization of Input During Web Page Generation (Stored Cross-Site Scripting) - CWE-79
Software Version: NOKIA NetAct 18A
NIST: https://nvd.nist.gov/vuln/detail/CVE-2021-26596
CVSv3: 5.4
Severity: Medium
Credits: Raffaella Robles, Andrea Carlo Maria Dattola, Massimiliano Brolli
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.