PatchSiren

Italtel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Italtel CVE published 2026-09-10

CVE-2022-26962

Italtel NFV 11.1.2-20210318 is vulnerable to Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementName parameter. This vulnerability allows a malicious user to inject arbitrary JavaScript, which will be triggered every time an authenticated user browses the page containing it. The vulnerability has a CVSS [truncated]