vendor:
Secure Mobile Access SMA
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)
79,352
CWE
Product Name: Secure Mobile Access SMA
Affected Version From: 8.1
Affected Version To: 8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:dell:sonicwall_secure_mobile_access_sma
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: SonicWALL SSL-VPN Web Server
2016
Dell SonicWALL Secure Mobile Access SMA 8.1 XSS And WAF CSRF
SonicWALL SMA suffers from a XSS issue due to a failure to properly sanitize user-supplied input to several parameters. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session. The WAF was bypassed via form-based CSRF.
Mitigation:
Ensure that user-supplied input is properly sanitized and that the WAF is properly configured to prevent CSRF attacks.