Retour à la veille

CVE-2026-92257

Publié : 15 septembre 2026
Modifié : 15 septembre 2026
Lien officiel NVD
Score CVSS
5.4
MEDIUM

Description détaillée

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Références et Patchs