Description
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
10.0.34.8215 and earlier versions
10.0.34.8223 and earlier versions
Credits
Brian Mariani of DigitalCanion SA - www.digitalcanion.com
References
psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0002