Cross-site Scripting Vulnerability in WatchGuard XTM Firewall
CVE-2014-6413
6.1MEDIUM
Summary
A Cross-site Scripting (XSS) vulnerability has been identified in WatchGuard XTM 11.8.3 that allows attackers to inject malicious scripts via the poll_name parameter in the firewall policy configuration. This flaw can be exploited to execute arbitrary JavaScript in the context of an affected user's session, potentially leading to unauthorized actions or exposure of sensitive information. Organizations using this version of WatchGuard XTM Firewall should implement immediate measures to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved