PT-2024-14961 · Forcepoint · Forcepoint Web Security

Harm Blankers

+1

·

Published

2024-08-22

·

Updated

2024-08-26

·

CVE-2023-6452

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Forcepoint Web Security versions prior to 8.5.6
Description The Forcepoint Web Security portal allows administrators to generate detailed reports on user requests made through the Web proxy. It has been determined that the user agent field in the Transaction Viewer is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability, which can be exploited by any user who can route traffic through the Forcepoint Web proxy. This issue enables unauthorized attackers to execute JavaScript within the browser context of a Forcepoint administrator, thereby allowing them to perform actions on the administrator's behalf. Such a breach could lead to unauthorized access or modifications, posing a significant security risk.
Recommendations For versions prior to 8.5.6, update to version 8.5.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Transaction Viewer to minimize the risk of exploitation. Avoid using the user agent field in the Transaction Viewer until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-6452

Affected Products

Forcepoint Web Security