MEDIUM🇵🇱 Wersja polska

CVE-2016-9834

CVSS 6.1v3.0pub. 2017-06-07upd. 2026-05-13

An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Sophos Cyberoam

    HW
    Sophos
    all versions
  • Sophos Cyberoam Firmware

    OS
    Sophos
    ≤ 10.6.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSFirewall
CWE
References

Related vulnerabilities

CVE-2019-17059CRITICAL9.8PL ✓same product

Sophos Cyberoam – command injection w panelu Web Admin i SSL VPN

CVE-2023-1671CRITICAL9.8⚠ KEVPL ✓same vendor

Pre-auth command injection w Sophos Web Appliance (RCE)

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same vendor

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2022-1040CRITICAL9.8⚠ KEVPL ✓same vendor

Authentication Bypass z możliwością RCE w Sophos Firewall

CVE-2020-29574CRITICAL9.8⚠ KEVPL ✓same vendor

SQL Injection w Sophos Cyberoam OS — zdalny dostęp bez uwierzytelnienia