CVE-2024-26156

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
are vulnerable to reflected cross site scripting (XSS) attacks in the 
method parameter. The ETIC RAS web server uses dynamic pages that gets 
their input from the client side and reflects the input in its response 
to the client.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
icscertCNA
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---