To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
No analysis available yet.
Vendor Solution
The following updates will fix this vulnerability: * SNS 5.1.0 * SNS 5.0.7 * SNS 4.8.17
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisories.stormshield.eu/2026-006 |
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stormshield
Stormshield stormshield Network Security |
|
| Vendors & Products |
Stormshield
Stormshield stormshield Network Security |
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface. | |
| Title | Possible XSS in the SNS web administration panel | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: airbus
Published:
Updated: 2026-09-04T14:41:07.268Z
Reserved: 2026-07-02T12:42:10.025Z
Link: CVE-2026-14466
Updated: 2026-09-04T14:40:59.135Z
Status : Received
Published: 2026-09-04T15:17:32.540
Modified: 2026-09-04T15:17:32.540
Link: CVE-2026-14466
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:06Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')