PT-2024-14961 · Forcepoint · Forcepoint Web Security
Harm Blankers
+1
·
Published
2024-08-22
·
Updated
2024-08-26
·
CVE-2023-6452
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Forcepoint Web Security versions prior to 8.5.6
Description
The Forcepoint Web Security portal allows administrators to generate detailed reports on user requests made through the Web proxy. It has been determined that the
user agent field in the Transaction Viewer is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability, which can be exploited by any user who can route traffic through the Forcepoint Web proxy. This issue enables unauthorized attackers to execute JavaScript within the browser context of a Forcepoint administrator, thereby allowing them to perform actions on the administrator's behalf. Such a breach could lead to unauthorized access or modifications, posing a significant security risk.Recommendations
For versions prior to 8.5.6, update to version 8.5.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Transaction Viewer to minimize the risk of exploitation. Avoid using the
user agent field in the Transaction Viewer until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forcepoint Web Security