Low severity3.3NVD Advisory· Published Mar 1, 2023· Updated Jun 17, 2026
CVE-2022-4901
CVE-2022-4901
Description
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.2.90+ 1 more
- (no CPE)range: <2.2.90
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrfnvdVendor Advisory
News mentions
0No linked articles in our index yet.