Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4901


Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.


Published

2023-03-01T19:15:25.793

Last Modified

2025-03-07T21:15:13.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sophos connect < 2.2.90 Yes

References