CVE-2020-36692: XSS
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36692?
CVE-2020-36692 is a reflected XSS via POST vulnerability in the report scheduler of Sophos Web Appliance versions older than 4.3.10.4.
How does CVE-2020-36692 impact Sophos Web Appliance?
CVE-2020-36692 allows the execution of JavaScript code in the victim's browser through a malicious form that needs to be manually submitted by the victim while logged into SWA.
What is the severity of CVE-2020-36692?
The severity of CVE-2020-36692 is medium, with a CVSS score of 5.4.
How can I fix the CVE-2020-36692 vulnerability?
To fix the CVE-2020-36692 vulnerability, it is recommended to update Sophos Web Appliance to version 4.3.10.4 or later.
Is there any additional information about CVE-2020-36692?
Yes, you can find more information about CVE-2020-36692 in the Sophos Security Advisory at the following URL: https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce