vendor:
Symantec Messaging Gateway
by:
Omur UGUR
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Symantec Messaging Gateway
Affected Version From: 10.7.2004
Affected Version To: 10.7.13
Patch Exists: YES
Related CWE: CVE-2022-25630
CPE: a:symantec:symantec_messaging_gateway
Platforms Tested: [relevant os]
2020
Symantec Messaging Gateway 10.7.4 – Stored Cross-Site Scripting (XSS)
An authenticated user can embed malicious content with XSS into the admin group policy page. Example payload: "/><svg/onload=prompt(document.domain)>"
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.