CVE-2023-33336

MEDIUM

Sophos Web Appliance <4.3.9.1 - XSS

Title source: llm
STIX 2.1

Description

Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.

Scores

CVSS v3 4.8
EPSS 0.0004
EPSS Percentile 14.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
sophos/web_appliance 4.3.9.1
Published Jun 30, 2023
Tracked Since Feb 18, 2026