THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-4804 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

[NVD] CVE-2025-4804 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

lownvdPublished 2025-05-16

CVE-2025-4804 CVSS: None Published: 2025-05-16T21:15:35.350

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-4804