VYPR
Medium severity4.7NVD Advisory· Published Nov 30, 2023· Updated Jun 17, 2026

CVE-2021-36806

CVE-2021-36806

Description

A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on

Sophos Email Appliance

older than version 4.5.3.4.

Affected products

3
  • cpe:2.3:a:sophos:email_appliance:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sophos:email_appliance:*:*:*:*:*:*:*:*range: <4.5.3.4
    • (no CPE)range: <4.5.3.4
    • (no CPE)range: 4.5.3.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.