First published: Sun Jan 14 2018(Updated: )
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL Analyzer | >=7.0<=7.2 | |
SonicWALL Analyzer | >=8.1<=8.4 | |
SonicWALL Global Management System | >=7.0<=7.2 | |
SonicWALL Global Management System | >=8.1<=8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5691 is a vulnerability in SonicWall Global Management System (GMS) 8.1 that allows for cross-site scripting (XSS) attacks via the 'newName' and 'Name' values of the '/sgms/TreeControl' module.
CVE-2018-5691 has a severity rating of 5.4 (medium).
SonicWall Analyzer versions 7.0 to 7.2, SonicWall GMS versions 7.0 to 7.2, SonicWall Analyzer versions 8.1 to 8.4, and SonicWall GMS versions 8.1 to 8.4 are affected by CVE-2018-5691.
To fix CVE-2018-5691, it is recommended to upgrade to a version that has the necessary security patches available.
More information about CVE-2018-5691 can be found in the release notes of SonicWall GMS OS 8.2, the SonicWall PSIRT website, and the Vulnerability Lab website.