PT-2015-5865 · Websense · Websense V-Series+1

Cengiz Han Sahin

·

Published

2015-03-26

·

Updated

2018-10-09

·

CVE-2015-2747

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Websense Triton version 7.8.3 Websense V-Series version 7.7
Description The issue allows remote attackers to inject arbitrary web script or HTML via a crafted email or HTTP request, triggering a DLP Policy. This occurs due to multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview.
Recommendations For Websense Triton version 7.8.3, update to a version that includes a fix for the XSS vulnerabilities in the DLP incident Forensics Preview. For Websense V-Series version 7.7, update to a version that includes a fix for the XSS vulnerabilities in the DLP incident Forensics Preview.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2747

Affected Products

Websense Triton
Websense V-Series