In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
2017-03-30T17:59:00.277
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sophos | web_appliance | ≤ 4.3.1.1 | Yes |