CVE-2023-6452

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows administrators to generate detailed reports on user requests made through the Web proxy. It has been determined that the "user agent" field in the Transaction Viewer is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability, which can be exploited by any user who can route traffic through the Forcepoint Web proxy. This vulnerability enables unauthorized attackers to execute JavaScript within the browser context of a Forcepoint administrator, thereby allowing them to perform actions on the administrator's behalf. Such a breach could lead to unauthorized access or modifications, posing a significant security risk. This issue affects Web Security: before 8.5.6.
Configurations

No configuration.

History

23 Aug 2024, 16:18

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site Scripting') en Forcepoint Web Security (Transaction Viewer) permite XSS Almacenado. El portal Forcepoint Web Security permite a los administradores generar informes detallados sobre las solicitudes de los usuarios realizadas a través del proxy web. Se ha determinado que el campo "agente de usuario" en el Visor de transacciones es vulnerable a una vulnerabilidad persistente de Cross-Site Scripting (XSS), que puede ser explotada por cualquier usuario que pueda enrutar el tráfico a través del proxy web de Forcepoint. Esta vulnerabilidad permite a atacantes no autorizados ejecutar JavaScript dentro del contexto del navegador de un administrador de Forcepoint, permitiéndoles así realizar acciones en nombre del administrador. Una infracción de este tipo podría dar lugar a modificaciones o accesos no autorizados, lo que plantearía un riesgo de seguridad importante. Este problema afecta a Web Security: versiones anteriores a 8.5.6.

22 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 16:15

Updated : 2024-08-23 16:18


NVD link : CVE-2023-6452

Mitre link : CVE-2023-6452

CVE.ORG link : CVE-2023-6452


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')