Vulnerabilities > Sophos > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-30 | CVE-2021-36806 | Cross-site Scripting vulnerability in Sophos Email Appliance 4.5.3.3 A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. | 6.1 |
2023-07-05 | CVE-2023-33335 | Cross-site Scripting vulnerability in Sophos Iview Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. | 6.1 |
2023-06-30 | CVE-2023-33336 | Cross-site Scripting vulnerability in Sophos web Appliance 4.3.9.1 Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes. | 4.8 |
2023-04-04 | CVE-2020-36692 | Cross-site Scripting vulnerability in Sophos web Appliance A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA. | 5.4 |
2023-03-01 | CVE-2022-48309 | Cross-Site Request Forgery (CSRF) vulnerability in Sophos Connect A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90. | 4.3 |
2023-03-01 | CVE-2022-48310 | Cleartext Storage of Sensitive Information vulnerability in Sophos Connect An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90. | 5.5 |
2023-03-01 | CVE-2022-4901 | Cross-site Scripting vulnerability in Sophos Connect Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim. | 6.1 |
2022-12-01 | CVE-2022-3711 | SQL Injection vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0 A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA. | 4.3 |
2022-03-29 | CVE-2022-0331 | Unspecified vulnerability in Sophos Sfos An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. | 5.3 |
2022-03-08 | CVE-2021-36809 | Unspecified vulnerability in Sophos SSL VPN Client A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client. | 6.0 |