CVE-2024-28803

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 13, 2025
Updated: Apr 2, 2025
CWE ID 79

Summary

CVE-2024-28803 is a newly disclosed cross-site scripting (XSS) vulnerability affecting Italtel S.p.A.'s i-MCS Network Functions Virtualization (NFV) version 12.1.0-20211215. Malicious actors can exploit this unauthenticated flaw to inject arbitrary web scripts or HTML into HTTP/POST parameters, potentially leading to code execution in the context of the victim's session. This poses a significant risk as successful attacks could result in data theft, unauthorized access, and other malicious activities. Users are advised to upgrade to a patched version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share