CVE-2013-2643 | Sophos Web Appliance 3.7.8.1 rss.php xss cross site scripting (ID 118969 / EDB-24932)
A vulnerability, which was classified as problematic, was found in Sophos Web Appliance 3.7.8.1. Affected is an unknown function of the file rss.php. The manipulation of the argument xss with the input %3Cscript%3Ealert%28String.fromCharCode%28120,%20115,%20115%29%29%3C/script%3E leads to cross site scripting.
This vulnerability is traded as CVE-2013-2643. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.