#VU87483 Stored cross-site scripting in SonicOS - CVE-2024-22397
Published: March 13, 2024
SonicOS
SonicWall
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the SSL-VPN Portal. A remote privileged user can permanently inject and execute arbitrary HTML and script code in user's browser when a specific URL is open.