Impact
This Cross‑Site Scripting vulnerability in SonicWall GMS 9.5.1 (Build 9510.1044) and earlier permits a remote attacker to inject and execute arbitrary JavaScript in the victim’s browser. Attackers could hijack the user session, steal credentials, or deliver phishing content. The flaw is a classic CWE‑79 incident.
Affected Systems
Impacting SonicWall GMS versions 9.5.1 and older. All deployments of SonicWall GMS with build 9510.1044 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate overall risk. The EPSS score of less than 1% shows very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to visit a malicious link or otherwise cause the GMS interface to render attacker‑supplied input. The attack vector is remote through crafted input to the GMS web interface.
OpenCVE Enrichment