Security Advisory
CVE-2017-6184
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machines interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.