Executive brief
Italtel NFV is a network function virtualization platform used by telecom operators to manage network services. A stored cross-site scripting (XSS) vulnerability in the configuration interface allows authenticated users to inject malicious JavaScript that executes whenever other administrators view the affected page, potentially leading to account compromise or unauthorized configuration changes.
Technical details
The vulnerability is a stored XSS flaw in the NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp endpoint, specifically in the name, username, or mrfAnnouncementName parameters. An authenticated attacker can inject arbitrary JavaScript code that is stored in the application database and executed in the browsers of other authenticated users who access the configuration page. The malicious payload persists and triggers on every page load, enabling persistent session hijacking, credential theft, or lateral movement. Fix/patch availability status is not confirmed in the advisory.
Affected products
- Italtel NFV 11.1.2-20210318
Timeline
- 2022-09-10: disclosed