CVE-2022-4901: XSS
Published Mar 1, 2023
·Updated
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
Affected Software
1 affected component
Sophos Connect<2.2.90
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-4901?
CVE-2022-4901 refers to multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90.
2
What is the severity of CVE-2022-4901?
The severity of CVE-2022-4901 is medium with a CVSS score of 6.1.
3
How do the vulnerabilities in CVE-2022-4901 work?
The vulnerabilities allow execution of Javascript code in the local UI through a malicious VPN configuration that needs to be manually loaded.
4
Which version of Sophos Connect is affected by CVE-2022-4901?
Sophos Connect versions older than 2.2.90 are affected by CVE-2022-4901.
5
How can I fix CVE-2022-4901?
To fix CVE-2022-4901, update your Sophos Connect installation to version 2.2.90 or newer.