First published: Fri Dec 09 2022(Updated: )
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Messaging Gateway | <10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25629 is a vulnerability that allows authenticated users with privileges to add/edit annotations on the Content tab in Symantec Messaging Gateway to craft malicious annotations that can be executed on the annotations page.
This vulnerability affects users of Symantec Messaging Gateway version 10.8.
CVE-2022-25629 has a severity rating of medium, with a CVSS score of 5.4.
To fix CVE-2022-25629, apply the latest security patch or update provided by Symantec.
More information about CVE-2022-25629 can be found in the Symantec support advisory at this link: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21115