Impact
The vulnerability allows a malicious script to be stored in the web administration panel of Stormshield SNS. An attacker who can inject a script into a group’s comments can cause that script to run whenever an administrator views the comment.
Affected Systems
The issue impacts Stormshield Network Security’s SNS product. Versions prior to SNS 5.1.0, SNS 5.0.7, and SNS 4.8.17 are vulnerable; updates to those releases provide the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an administrator with sufficient permissions to inject the script; the vulnerability is not exploitable by unauthenticated users.
OpenCVE Enrichment