Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Affected products
- SonicWall / SonicOS7.0.1-5145 and earlier versions – 7.0.1-5145 and earlier versions
- SonicWall / SonicOS7.1.1-7047 and earlier versions – 7.1.1-7047 and earlier versions