PT-2018-17088 · Sonicwall · Sonicwall Global Management System
Benjamin Kunz Mejri
·
Published
2018-01-14
·
Updated
2019-03-04
·
CVE-2018-5691
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SonicWall Global Management System (GMS) version 8.1
Description:
The issue concerns an XSS vulnerability. It is exploited via the
newName and Name values of the "/sgms/TreeControl" module.Recommendations:
For SonicWall Global Management System (GMS) version 8.1, consider restricting access to the
/sgms/TreeControl module until a patch is available. As a temporary workaround, avoid using the newName and Name values in the affected module to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicwall Global Management System