Executive brief
Italtel NetMatch-S is a network management system used to configure and monitor telecommunications infrastructure. The system contains multiple stored cross-site scripting (XSS) vulnerabilities in web administration pages that allow authenticated users to inject malicious JavaScript code. When other administrators access affected pages, the injected code executes in their browsers, potentially compromising their sessions or enabling credential theft.
Technical details
Multiple stored XSS vulnerabilities exist in Italtel NetMatch-S 5.0.0-20200703 in the backup_restore.jsp and storage.jsp pages within the NMSCI-WebGui interface. The vulnerabilities stem from insufficient input validation on the "name" parameter, allowing authenticated users to inject arbitrary JavaScript that is stored in the application and executed when other authenticated users view the affected pages. The attack requires existing authentication to the web interface and affects any administrator who browses the vulnerable pages afterward. An attacker with valid credentials can establish persistent malicious behavior without code-level exploitation, relying on stored payload execution.
Affected products
- Italtel NetMatch-S 5.0.0-20200703
Timeline
- 2022-09-04: disclosed