CVE-2016-2046: XSS
Published Feb 17, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected Software
1 affected component
Sophos Unified Threat Management<=9.351
Event History
Feb 17, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2046?
The severity of CVE-2016-2046 is considered moderate due to its potential for Cross-site scripting attacks.
2
How do I fix CVE-2016-2046?
To fix CVE-2016-2046, upgrade Sophos Unified Threat Management to version 9.353 or later.
3
What software is affected by CVE-2016-2046?
CVE-2016-2046 affects Sophos Unified Threat Management software versions prior to 9.353.
4
What impact does CVE-2016-2046 have?
CVE-2016-2046 allows remote attackers to inject arbitrary web scripts or HTML into the UserPortal page.
5
When was CVE-2016-2046 disclosed?
CVE-2016-2046 was disclosed in February 2016.