First published: Thu Jul 29 2021(Updated: )
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Unified Threat Management | <9.706 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25273 is a vulnerability that allows for stored XSS (Cross-Site Scripting) attacks to be executed as an administrator in the quarantined email detail view in Sophos UTM before version 9.706.
The severity of CVE-2021-25273 is medium with a CVSS (Common Vulnerability Scoring System) score of 4.8.
CVE-2021-25273 affects Sophos UTM before version 9.706, specifically in the quarantined email detail view.
The stored XSS vulnerability in CVE-2021-25273 can be exploited by executing malicious scripts as an administrator in the quarantined email detail view.
Yes, a patch for CVE-2021-25273 is available in Sophos UTM version 9.706 or later.