CVE-2024-26157

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
are vulnerable to reflected cross site scripting (XSS) attacks in get 
view method under view parameter. The ETIC RAS web server uses dynamic 
pages that get their input from the client side and reflect the input in
 their response to the client.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
icscertCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---