Stored XSS Vulnerability in Stormshield SNS 3.8.0 Admin Login Panel
CVE-2020-11711

4.8MEDIUM

Key Information:

Vendor
CVE Published:
25 August 2023

What is CVE-2020-11711?

An issue in Stormshield SNS 3.8.0 allows authenticated users to exploit the admin login panel through stored XSS attacks. By uploading a malicious disclaimer file from the admin interface, attackers can inject harmful HTML and JavaScript, executing in the browsers of administrators. This vulnerability also exposes an unsecured authentication form in the SSL VPN captive portal, enabling potential theft of saved credentials. In scenarios where admins save their passwords in the unsecured form, attackers leveraging the XSS could capture these details without user involvement. Furthermore, the exploitation extends to altering the authentication form by introducing a malicious version, further compromising the admin's security.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.