Stored XSS Vulnerability in Stormshield SNS 3.8.0 Admin Login Panel
CVE-2020-11711
4.8MEDIUM
What is CVE-2020-11711?
An issue in Stormshield SNS 3.8.0 allows authenticated users to exploit the admin login panel through stored XSS attacks. By uploading a malicious disclaimer file from the admin interface, attackers can inject harmful HTML and JavaScript, executing in the browsers of administrators. This vulnerability also exposes an unsecured authentication form in the SSL VPN captive portal, enabling potential theft of saved credentials. In scenarios where admins save their passwords in the unsecured form, attackers leveraging the XSS could capture these details without user involvement. Furthermore, the exploitation extends to altering the authentication form by introducing a malicious version, further compromising the admin's security.
