CVE-2018-5691: XSS
SonicWall Global Management System (GMS) 8.1 has XSS via the newName and Name values of the /sgms/TreeControl module.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5691?
CVE-2018-5691 is a vulnerability in SonicWall Global Management System (GMS) 8.1 that allows for cross-site scripting (XSS) attacks via the 'newName' and 'Name' values of the '/sgms/TreeControl' module.
How severe is CVE-2018-5691?
CVE-2018-5691 has a severity rating of 5.4 (medium).
What software versions are affected by CVE-2018-5691?
SonicWall Analyzer versions 7.0 to 7.2, SonicWall GMS versions 7.0 to 7.2, SonicWall Analyzer versions 8.1 to 8.4, and SonicWall GMS versions 8.1 to 8.4 are affected by CVE-2018-5691.
How can I fix CVE-2018-5691?
To fix CVE-2018-5691, it is recommended to upgrade to a version that has the necessary security patches available.
Where can I find more information about CVE-2018-5691?
More information about CVE-2018-5691 can be found in the release notes of SonicWall GMS OS 8.2, the SonicWall PSIRT website, and the Vulnerability Lab website.