A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
2022-12-01T18:15:10.397
2025-04-24T20:15:24.583
Modified
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sophos | xg_firewall_firmware | ≤ 19.0 | Yes |
Hardware | sophos | xg_firewall | - | No |