CVE-2012-3238

Astaro Security Gateway <8.305 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.

Scores

EPSS 0.0054
EPSS Percentile 67.3%

Classification

CWE
CWE-79
Status published

Affected Products (11)

astaro/security_gateway_software < 8.3
astaro/security_gateway
sophos/unified_threat_management_software < 8.3
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
n/a/n/a

Timeline

Published Jul 09, 2012
Tracked Since Feb 18, 2026