---
id: CVE-2022-26961
title: >-
  Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under
  NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and
  NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter
summary: >-
  Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under
  NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and
  NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious
  user leveraging this vulnerability coul…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-09-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T19:17:25.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-26961'
references:
  - url: >-
      https://www.gruppotim.it/it/footer/red-team/2022/CVE-2022-26961-Italtel-NETMATCH-S-CLOUD-INSIDE-VNF.html
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T19:00:37.846038Z'
epss: 0.0014
epssPercentile: 0.02771
ingestedAt: '2026-09-08T20:10:03.168Z'
---

## Overview

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
