CyberRota Analysis
AI-GeneratedStormshield's web administration panel is vulnerable to stored cross-site scripting (XSS), allowing an authenticated administrator to inject malicious scripts into group comments. This could lead to unauthorized actions or data exposure when other users access the compromised comments. Organizations using Stormshield's web services should prioritize remediation to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.