CVE-2022-26961
Received Received - Intake

Multiple Stored XSS in Italtel NetMatch-S 5.0.0

Vulnerability report for CVE-2022-26961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
italtel netmatch-s 5.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Italtel NetMatch-S version 5.0.0-20200703. It allows attackers to inject malicious JavaScript code via the 'name' parameter in specific pages like backup_restore.jsp and storage.jsp. The injected script executes whenever an authenticated user views the affected page.

Detection Guidance

This vulnerability involves stored XSS in Italtel NetMatch-S 5.0.0-20200703 via the name parameter in specific JSP files. Detection requires manual inspection of the affected pages (backup_restore.jsp and storage.jsp) for malicious JavaScript payloads in the name parameter. No specific commands are provided in the context.

Impact Analysis

An attacker could steal session cookies, redirect users to malicious sites, or perform actions on behalf of users. Since the payload is stored, it affects all users who access the compromised page. This could lead to unauthorized access to sensitive data or account takeover.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data through unauthorized script execution. For HIPAA, it may compromise protected health information if exploited. Both standards require protecting against XSS to ensure data confidentiality and integrity.

Mitigation Strategies

Immediately update Italtel NetMatch-S to the latest patched version. If an update is unavailable, disable access to the vulnerable pages NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp until a fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2022-26961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart