An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the template preview. The following versions fix this: 3.7.42, 3.11.30, 4.3.25, and 4.7.5.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://advisories.stormshield.eu/2024-007 |
History
Wed, 30 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-15T00:00:00
Updated: 2024-10-30T16:59:21.473Z
Reserved: 2024-04-07T00:00:00
Link: CVE-2024-31946
Vulnrichment
Updated: 2024-08-02T01:59:50.836Z
NVD
Status : Awaiting Analysis
Published: 2024-07-15T19:15:02.503
Modified: 2024-10-30T17:35:06.460
Link: CVE-2024-31946
Redhat
No data.