CVE-2023-6452
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
22/08/2024
Last modified:
23/08/2024
Description
Improper Neutralization of Input During Web Page Generation (&#39;Cross-site Scripting&#39;) vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS.<br />
<br />
<br />
<br />
<br />
<br />
The<br />
Forcepoint Web Security portal allows administrators to generate <br />
detailed reports on user requests made through the Web proxy. It has <br />
been determined that the "user agent" field in the Transaction Viewer is<br />
vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability, <br />
which can be exploited by any user who can route traffic through the <br />
Forcepoint Web proxy.<br />
<br />
This <br />
vulnerability enables unauthorized attackers to execute JavaScript <br />
within the browser context of a Forcepoint administrator, thereby <br />
allowing them to perform actions on the administrator&#39;s behalf. Such a <br />
breach could lead to unauthorized access or modifications, posing a <br />
significant security risk.<br />
<br />
<br />
<br />
<br />
<br />
<br />
This issue affects Web Security: before 8.5.6.
Impact
Base Score 3.x
9.60
Severity 3.x
CRITICAL



