Description
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Stormshield / Stormshield Network Security4.8.0 – 4.8.16
- Stormshield / Stormshield Network Security5.0.0 – 5.0.6
- Stormshield / Stormshield Network Security4.8.17 – 4.8.17
- Stormshield / Stormshield Network Security5.0.7 – 5.0.7
- Stormshield / Stormshield Network Security5.1.0 – 5.1.0
References
- VENDOR_ADVISORYhttps://advisories.stormshield.eu/2026-006
Updated 5m ago · 8 sources