← Back

Italtel

italtel

15 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Embrace
embrace
I Mcs Nfv
i-mcs_nfv
Netmatch S Ci
netmatch-s_ci

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Italtel
1I Mcs Nfv
Oct 14, 2025
Mar 13, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter
1Italtel
1Embrace
Oct 29, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed th...Show more
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web sites, stored in web logs, or otherwise recorded in other sources. If the query string contains sensitive information such as session identifiers, then attackers can use this information to launch further attacks. Because the access token in sent in GET requests, this vulnerability could lead to complete account takeover.Show less
1Italtel
1I Mcs Nfv
Oct 14, 2025
Jul 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.
1Italtel
1I Mcs Nfv
Oct 14, 2025
Jul 29, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
1Italtel
1I Mcs Nfv
Oct 14, 2025
Jul 29, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.
1Italtel
1Embrace
May 21, 2025
May 23, 2024
N/A· v4
4.1 MEDIUM· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands...Show more
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.Show less
1Italtel
1Embrace
Mar 13, 2025
May 21, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. T...Show more
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.Show less
1Italtel
1Embrace
May 21, 2025
May 21, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parame...Show more
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.Show less
1Italtel
1Embrace
Mar 13, 2025
May 21, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft s...Show more
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft specific requests in order to make the application generate an error. Inside an error message, some information about the server is revealed, such as the absolute path of the source code of the application. This kind of information can help an attacker to perform other attacks against the system. This can be exploited without authentication.Show less
1Italtel
1Embrace
Mar 14, 2025
May 21, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access...Show more
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web application fills the edit form with the current credentials for the email account, including the cleartext password.Show less
1Italtel
1Embrace
May 21, 2025
Apr 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Italtel
1Embrace
May 21, 2025
Apr 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
1Italtel
1Netmatch S Ci
Mar 28, 2025
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp via the name or actLine parameter. An at...Show more
Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp via the name or actLine parameter. An attacker leveraging this vulnerability could inject arbitrary JavaScript. The payload would then be triggered every time an authenticated user browses the page containing it.Show less
1Italtel
1Netmatch S Ci
Mar 28, 2025
Jan 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a...Show more
Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.Show less
1Italtel
1Netmatch S Ci
Mar 28, 2025
Jan 27, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to v...Show more
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system configuration, bypassing all controls (without checking for user identity).Show less