PT-2020-7725 · Watchguard · Watchguard Xtm
Published
2020-02-07
·
Updated
2020-02-11
·
CVE-2014-6413
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WatchGuard XTM version 11.8.3
Description
A Cross-site Scripting (XSS) issue exists via the
poll name parameter in the "firewall/policy script" API endpoint.Recommendations
For WatchGuard XTM version 11.8.3, avoid using the
poll name parameter in the affected script until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Watchguard Xtm