PT-2017-10366 · Sophos · Sophos Cyberoam

Bhadresh Patel

·

Published

2017-06-07

·

Updated

2017-06-14

·

CVE-2016-9834

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sophos Cyberoam firewall devices with firmware through 10.6.4
Description The issue allows remote attackers to execute arbitrary client-side script on vulnerable installations. User interaction is required, where the target must visit a malicious page or open a malicious file. The flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. The applicationname and username GET parameters are improperly sanitized, allowing an attacker to inject arbitrary JavaScript into the page. This can be abused to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.
Recommendations For Sophos Cyberoam firewall devices with firmware through 10.6.4, consider restricting access to the LiveConnectionDetail.jsp application until a patch is available. As a temporary workaround, avoid using the applicationname and username parameters in the affected API endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9834

Affected Products

Sophos Cyberoam