An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the template preview. The following versions fix this: 3.7.42, 3.11.30, 4.3.25, and 4.7.5.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.stormshield.eu/2024-007 |
|
History
Wed, 30 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T16:59:21.473Z
Reserved: 2024-04-07T00:00:00.000Z
Link: CVE-2024-31946
Updated: 2024-08-02T01:59:50.836Z
Status : Awaiting Analysis
Published: 2024-07-15T19:15:02.503
Modified: 2024-11-21T09:14:10.573
Link: CVE-2024-31946
No data.
OpenCVE Enrichment
No data.
Weaknesses