CVE-2014-2849 | Sophos Web Appliance up to 3.8.1 Change Password Dialog Box /index.php c access control (Article 120230 / EDB-32789)
A vulnerability, which was classified as critical, was found in Sophos Web Appliance up to 3.8.1. Affected is an unknown function of the file /index.php of the component Change Password Dialog Box. The manipulation of the argument c with the input change_password leads to improper access controls.
This vulnerability is traded as CVE-2014-2849. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.