CVE-2017-9523: XSS
Published Jun 9, 2017
·Updated
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
Affected Software
1 affected component
Sophos Web Appliance<=4.3.1.4
Event History
Jun 9, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9523?
CVE-2017-9523 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-9523?
To fix CVE-2017-9523, upgrade the Sophos Web Appliance to version 4.3.2 or later.
3
What issue does CVE-2017-9523 address?
CVE-2017-9523 addresses a vulnerability that allows XSS in the FTP redirect page of the Sophos Web Appliance.
4
What versions of Sophos Web Appliance are affected by CVE-2017-9523?
Sophos Web Appliance versions prior to 4.3.2, especially those up to 4.3.1.4, are affected by CVE-2017-9523.
5
Is CVE-2017-9523 a common vulnerability?
CVE-2017-9523 is not among the most commonly reported vulnerabilities but it poses real risks due to its XSS exploitation potential.