CVE-2012-3238
Astaro Security Gateway <8.305 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
Scores
EPSS
0.0054
EPSS Percentile
67.3%
Classification
CWE
CWE-79
Status
published
Affected Products (11)
astaro/security_gateway_software
< 8.3
astaro/security_gateway
sophos/unified_threat_management_software
< 8.3
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
n/a/n/a
Timeline
Published
Jul 09, 2012
Tracked Since
Feb 18, 2026