packetstormsecurity.com
http://packetstormsecurity.com/files/171781/Symantec-Messaging-Gateway-10.7.4-Cross-Site-Scripting.html CVE-2022-25630
MEDIUM
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
Record summary
CVE-2022-25630 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
An authenticated user can embed malicious content with XSS into the admin group policy page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Symantec Messaging Gateway | CVE List | All releases prior to SMG 10.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSymantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby omurugurNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-25630 support.broadcom.com
https://support.broadcom.com/external/content/SecurityAdvisories/0/21117 support.broadcom.com
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21117