CVE-2023-33335

MEDIUM

Sophos iView - Stored Cross-Site Scripting via grpname Parameter

Title source: llm
STIX 2.1

Description

Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
sophos/iview
Published Jul 05, 2023
Tracked Since Feb 18, 2026