CVE-2022-25629: Symantec Messaging Gateway
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
Affected products
- Symantec Messaging Gateway: before 10.8 (fixed in 10.8)
Published 2022-12-09. Last modified 2026-06-17.