Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Modrnproph3T

#43619of 53,611
6.1Total CVSS
Vulnerabilities · 1
PT-2024-25474
6.1
2024-04-06
Iboss · Iboss Secure Web Gateway · CVE-2024-3378
**Name of the Vulnerable Software and Affected Versions** iboss Secure Web Gateway versions up to 10.1 **Description** A vulnerability has been found in the iboss Secure Web Gateway, affecting an unknown functionality of the file "/login" of the component Login Portal. The manipulation of the `redirectUrl` argument leads to cross-site scripting. The attack can be launched remotely. **Recommendations** For iboss Secure Web Gateway versions up to 10.1, upgrade to version 10.2.0.160 to address this issue. As a temporary workaround, consider restricting access to the "/login" endpoint or disabling the manipulation of the `redirectUrl` argument until the upgrade is applied.