← back
CVE-2021-25268high

CVE-2021-25268

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.4epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
Sophos · Sophos Firewall