Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.
| Software | From | Fixed in |
|---|---|---|
| watchguard / fireware | 11.7.2 | 11.7.2.x |
| watchguard / fireware | 11.6 | 11.6.x |
| watchguard / fireware | 11.6.3 | 11.6.3.x |
| watchguard / fireware | 11.7 | 11.7.x |
| watchguard / fireware | 11.8 | 11.8.x |
| watchguard / fireware | 11.6.5 | 11.6.5.x |
| watchguard / fireware | 11.7.4 | 11.7.4.x |
| watchguard / fireware | - | 11.8.1.x |
| watchguard / fireware | 11.6.1 | 11.6.1.x |
| watchguard / fireware | 11.7.3 | 11.7.3.x |
| watchguard / fireware | 11.6.6 | 11.6.6.x |