CVE-2021-25267: XSS
Published May 5, 2022
·Updated
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
Affected Software
2 affected components
Sophos Firewall Firmware<19.0
Sophos Firewall
Event History
May 5, 2022
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2021-25267?
The severity of CVE-2021-25267 is high with a CVSS score of 8.4.
2
What is the impact of CVE-2021-25267?
CVE-2021-25267 allows for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
3
How can I fix CVE-2021-25267?
Upgrade to Sophos Firewall version 19.0 or later to fix CVE-2021-25267.
4
Is Sophos Firewall affected by CVE-2021-25267?
Yes, Sophos Firewall older than version 19.0 GA is affected by CVE-2021-25267.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-25267?
The Common Weakness Enumeration (CWE) ID for CVE-2021-25267 is 79.