NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia nsp |
|
| Vendors & Products |
Nokia
Nokia nsp |
Mon, 31 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Mon, 31 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content. | |
| Title | A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP | |
| References |
|
Status: PUBLISHED
Assigner: Nokia
Published: 2026-08-31T06:35:32.425Z
Updated: 2026-08-31T14:33:52.270Z
Reserved: 2026-04-13T11:28:52.516Z
Link: CVE-2026-40464
Updated: 2026-08-31T14:33:48.365Z
Status : Received
Published: 2026-08-31T07:17:43.750
Modified: 2026-08-31T15:17:15.910
Link: CVE-2026-40464
No data.