April 4, 2023, 10:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.

browser code cve javascript malicious reflected xss report scheduler sophos sophos web appliance victim vulnerability web xss

Network Security Tools Engineer / Systems Engineer

@ Node.Digital | Arlington, Virginia, United States

Scrum Master II - Global Information Security PMO

@ Marriott International | Bethesda, MD, United States

Principle Security Incident Response Analyst

@ Oracle | United States

Cyber Network Engineer

@ Peraton | Aberdeen Proving Ground, MD, United States

Red Team Operator: Assessments & Exercises Vice President

@ JPMorgan Chase & Co. | Columbus, OH, United States

Cybersecurity Undergraduate - Internship

@ esure Group | Reigate, United Kingdom