← Retour aux CVEs
CVE-2021-35483
MEDIUM4.1
Description
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed.
Details CVE
Score CVSS v3.14.1
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie3/3/2026
Derniere modification3/5/2026
Sourcenvd
Observations honeypot0
Produits affectes
nokia:impact
Faiblesses (CWE)
CWE-79
References
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.