CVE-2022-25629: XSS
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25629?
CVE-2022-25629 is a vulnerability that allows authenticated users with privileges to add/edit annotations on the Content tab in Symantec Messaging Gateway to craft malicious annotations that can be executed on the annotations page.
Who is affected by CVE-2022-25629?
This vulnerability affects users of Symantec Messaging Gateway version 10.8.
What is the severity of CVE-2022-25629?
CVE-2022-25629 has a severity rating of medium, with a CVSS score of 5.4.
How can I fix CVE-2022-25629?
To fix CVE-2022-25629, apply the latest security patch or update provided by Symantec.
Where can I find more information about CVE-2022-25629?
More information about CVE-2022-25629 can be found in the Symantec support advisory at this link: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21115