CVE-2023-33336: Sophos Web Appliance

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.

Affected products

  • Sophos Web Appliance: version 4.3.9.1 only

Published 2023-06-30. Last modified 2026-06-17.