First published: Fri Jun 09 2017(Updated: )
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Web Appliance Firmware | <=4.3.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9523 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2017-9523, upgrade the Sophos Web Appliance to version 4.3.2 or later.
CVE-2017-9523 addresses a vulnerability that allows XSS in the FTP redirect page of the Sophos Web Appliance.
Sophos Web Appliance versions prior to 4.3.2, especially those up to 4.3.1.4, are affected by CVE-2017-9523.
CVE-2017-9523 is not among the most commonly reported vulnerabilities but it poses real risks due to its XSS exploitation potential.