Skip to main content

Vendor archive

italtel CVEs

Beta · best-effort

15 CVEs tagged to vendor italtel2 Critical, 6 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-28803

Published Mar 13, 2025

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31842

Published Aug 20, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28806

Published Jul 29, 2024

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28805

Published Jul 29, 2024

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28804

Published Jul 29, 2024

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31843

Published May 23, 2024

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allow…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31847

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31845

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31844

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31840

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31846

Published Apr 19, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31841

Published Apr 19, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39813

Published Jan 27, 2023

Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39812

Published Jan 27, 2023

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39811

Published Jan 27, 2023

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1