Security Advisory
CVE-2014-2849
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.