cve/2024/CVE-2024-22397.md
2024-05-25 21:48:12 +02:00

842 B

CVE-2024-22397

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.

POC

Reference

No PoCs from references.

Github