The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia impact |
|
| Vendors & Products |
Nokia
Nokia impact |
Tue, 03 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-03-03T00:00:00.000Z
Updated: 2026-03-04T15:55:11.671Z
Reserved: 2021-06-24T00:00:00.000Z
Link: CVE-2021-35483
Updated: 2026-03-04T15:53:41.327Z
Status : Undergoing Analysis
Published: 2026-03-03T18:16:20.077
Modified: 2026-03-04T16:16:22.083
Link: CVE-2021-35483
No data.