CVE-2014-2849 | Sophos Web Appliance up to 3.8.1 Change Password Dialog Box /index.php c access control (Article 120230 / EDB-32789)
A vulnerability marked as critical has been reported in Sophos Web Appliance up to 3.8.1. This issue affects some unknown processing of the file /index.php of the component Change Password Dialog Box. The manipulation of the argument c with the input change_password leads to improper access controls.
This vulnerability is listed as CVE-2014-2849. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.