Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
oryginał ENCVSS Vector
AV:N/AC:M/Au:N/C:N/I:P/A:NAstaro Security Gateway
HWAstarowszystkie wersjeAstaro Security Gateway Software
APPAstaro≤ 8.3Sophos Unified Threat Management
HWSophos110120220320425525625Sophos Unified Threat Management Software
APPSophos≤ 8.3
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
XSS
CWE
Powiązane podatności
CVE-2020-25223CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Sophos SG UTM WebAdmin — command injection bez uwierzytelnienia
CVE-2022-0386HIGH8.8ten sam produkt
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to ex...
CVE-2015-7547HIGH8.1ten sam produkt
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in...
CVE-2016-0778HIGH8.1ten sam produkt
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, an...
CVE-2014-2537HIGH7.8ten sam produkt
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denia...