A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
| Vendor | Product | Versions |
|---|---|---|
| sonicwall | email security | — |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| sonicwall | email security | cert_advisory | 90% |
Added vendor and product information, updated severity to LOW, and marked the vulnerability as actively exploited with an exploit available.
Initial creation