Vulnerabilities > Italtel

DATE CVE VULNERABILITY TITLE RISK
2023-01-27 CVE-2022-39811 Missing Authorization vulnerability in Italtel Netmatch-S CI 5.2.020211008
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader.
network
low complexity
italtel CWE-862
critical
9.1
2023-01-27 CVE-2022-39812 Path Traversal vulnerability in Italtel Netmatch-S CI 5.2.020211008
Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader.
network
low complexity
italtel CWE-22
7.5
2023-01-27 CVE-2022-39813 Cross-site Scripting vulnerability in Italtel Netmatch-S CI 5.2.020211008
Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp via the name or actLine parameter.
network
low complexity
italtel CWE-79
6.1