CVE-2020-36692: Sophos Web Appliance
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
Affected products
- Sophos Web Appliance: before 4.3.10.4 (fixed in 4.3.10.4)
Published 2023-04-04. Last modified 2026-06-17.