CVE-2021-36806: XSS
Published Nov 30, 2023
·Updated
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on
Sophos Email Appliance
older than version 4.5.3.4.
Affected Software
1 affected component
Sophos Email Appliance<4.5.3.4
Event History
Nov 30, 2023
CVE Published
09:41 AM
Data Sourced
09:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-36806.
2
What is the severity of CVE-2021-36806?
The severity of CVE-2021-36806 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2021-36806?
The affected software for CVE-2021-36806 is Sophos Email Appliance older than version 4.5.3.4.
4
How can the vulnerability in CVE-2021-36806 be exploited?
The vulnerability in CVE-2021-36806 can be exploited by tricking the victim into clicking a malicious link to an error page on Sophos Email Appliance.
5
Is there a fix available for CVE-2021-36806?
Yes, a fix is available for CVE-2021-36806 in Sophos Email Appliance version 4.5.3.4 or later.