Description
A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected products
- Stormshield / Stormshield Network Security4.3.0 – 4.3.41
- Stormshield / Stormshield Network Security4.8.0 – 4.8.15
- Stormshield / Stormshield Network Security5.0.0 – 5.0.5
References
- VENDOR_ADVISORYhttps://advisories.stormshield.eu/2026-003/
Updated 5m ago · 8 sources