An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the template preview. The following versions fix this: 3.7.42, 3.11.30, 4.3.25, and 4.7.5.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://advisories.stormshield.eu/2024-007 |
|
History
Wed, 30 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-15T00:00:00.000Z
Updated: 2024-10-30T16:59:21.473Z
Reserved: 2024-04-07T00:00:00.000Z
Link: CVE-2024-31946
Updated: 2024-08-02T01:59:50.836Z
Status : Deferred
Published: 2024-07-15T19:15:02.503
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-31946
No data.
ReportizFlow