CVE-2021-25273: XSS
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25273?
CVE-2021-25273 is a vulnerability that allows for stored XSS (Cross-Site Scripting) attacks to be executed as an administrator in the quarantined email detail view in Sophos UTM before version 9.706.
What is the severity of CVE-2021-25273?
The severity of CVE-2021-25273 is medium with a CVSS (Common Vulnerability Scoring System) score of 4.8.
How does CVE-2021-25273 affect Sophos Unified Threat Management (UTM)?
CVE-2021-25273 affects Sophos UTM before version 9.706, specifically in the quarantined email detail view.
How can the stored XSS vulnerability in CVE-2021-25273 be exploited?
The stored XSS vulnerability in CVE-2021-25273 can be exploited by executing malicious scripts as an administrator in the quarantined email detail view.
Is there a fix or patch available for CVE-2021-25273?
Yes, a patch for CVE-2021-25273 is available in Sophos UTM version 9.706 or later.