Reflected XSS Vulnerability in Sophos Web Appliance
CVE-2020-36692
5.4MEDIUM
What is CVE-2020-36692?
A reflected XSS vulnerability exists in the report scheduler of Sophos Web Appliance, allowing attackers to execute JavaScript in a victim's browser. This occurs when a victim submits a maliciously crafted form while logged in to the appliance. Users of Sophos Web Appliance versions prior to 4.3.10.4 should take immediate action to update their software to mitigate the risk.
Affected Version(s)
Sophos Web Appliance < 4.3.10.4