CVE-2022-26961

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

  • Published Sep 4, 2026
  • CVSS 5.4 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

CVE-2022-26961 at the National Vulnerability Database