CVE-2022-48309: CSRF
Published Mar 1, 2023
·Updated
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
Affected Software
1 affected component
Sophos Connect<2.2.90
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-48309?
CVE-2022-48309 is a CSRF vulnerability in Sophos Connect versions older than 2.2.90.
2
How does CVE-2022-48309 affect Sophos Connect?
CVE-2022-48309 allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
3
What is the severity of CVE-2022-48309?
The severity of CVE-2022-48309 is medium with a CVSS score of 4.3.
4
How can I fix CVE-2022-48309?
To fix CVE-2022-48309, update Sophos Connect to version 2.2.90 or newer.
5
Where can I find more information about CVE-2022-48309?
You can find more information about CVE-2022-48309 in the Sophos Security Advisory: https://www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrf