First published: Wed Mar 01 2023(Updated: )
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Connect | <2.2.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48309 is a CSRF vulnerability in Sophos Connect versions older than 2.2.90.
CVE-2022-48309 allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
The severity of CVE-2022-48309 is medium with a CVSS score of 4.3.
To fix CVE-2022-48309, update Sophos Connect to version 2.2.90 or newer.
You can find more information about CVE-2022-48309 in the Sophos Security Advisory: https://www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrf