Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Nokia Subscribe
Filtered by product Netact
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26597 1 Nokia 1 Netact 2021-04-01 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
CVE-2021-26596 1 Nokia 1 Netact 2021-04-01 3.5 LOW 5.4 MEDIUM
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.