Vulnerabilities
Vulnerable Software
Sophos:  >> Web Appliance  >> 4.3.10  Security Vulnerabilities
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
CVSS Score
6.5
EPSS Score
0.002
Published
2023-04-04
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
CVSS Score
7.2
EPSS Score
0.001
Published
2023-04-04
CVE-2023-1671
Known exploited
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
CVSS Score
9.8
EPSS Score
0.943
Published
2023-04-04


Contact Us

Shodan ® - All rights reserved