CVE-2022-3709: XSS
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3709?
CVE-2022-3709 is a stored XSS vulnerability that allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
How can the CVE-2022-3709 vulnerability be exploited?
The CVE-2022-3709 vulnerability can be exploited by an admin to escalate their privileges to super-admin through the Webadmin import group wizard in Sophos Firewall releases older than version 19.5 GA.
What is the severity of CVE-2022-3709?
CVE-2022-3709 has a severity rating of high with a CVSS score of 8.4.
Which versions of Sophos Firewall are affected by CVE-2022-3709?
Sophos Firewall releases older than version 19.5 GA are affected by CVE-2022-3709.
How can I fix the CVE-2022-3709 vulnerability?
To fix the CVE-2022-3709 vulnerability, it is recommended to upgrade Sophos Firewall to version 19.5 GA or newer.