A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Sophos
Published: 2023-04-04T00:00:00
Updated: 2024-08-04T17:37:05.255Z
Reserved: 2023-03-28T00:00:00
Link: CVE-2020-36692
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-04T10:15:07.057
Modified: 2024-11-21T05:30:04.840
Link: CVE-2020-36692
Redhat
No data.