Vulnerabilities > Sophos > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2021-36806 Cross-site Scripting vulnerability in Sophos Email Appliance
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.
network
low complexity
sophos CWE-79
6.1
2023-07-05 CVE-2023-33335 Cross-site Scripting vulnerability in Sophos Iview
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
network
low complexity
sophos CWE-79
6.1
2023-06-30 CVE-2023-33336 Cross-site Scripting vulnerability in Sophos web Appliance 4.3.9.1
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
network
low complexity
sophos CWE-79
4.8
2023-03-01 CVE-2022-48309 Cross-Site Request Forgery (CSRF) vulnerability in Sophos Connect
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
network
low complexity
sophos CWE-352
4.3
2023-03-01 CVE-2022-48310 Cleartext Storage of Sensitive Information vulnerability in Sophos Connect
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
local
low complexity
sophos CWE-312
5.5
2023-03-01 CVE-2022-4901 Cross-site Scripting vulnerability in Sophos Connect
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
network
low complexity
sophos CWE-79
6.1
2022-12-01 CVE-2022-3711 SQL Injection vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
network
low complexity
sophos CWE-89
4.3
2022-05-05 CVE-2021-25268 Cross-site Scripting vulnerability in Sophos Firewall Firmware
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
network
sophos CWE-79
6.0
2022-03-29 CVE-2022-0331 Unspecified vulnerability in Sophos Sfos
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
network
low complexity
sophos
5.3
2022-03-22 CVE-2022-0386 SQL Injection vulnerability in Sophos Unified Threat Management
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
network
low complexity
sophos CWE-89
6.5