CVE-2015-2747: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via a crafted (1) email or (2) HTTP request, which triggers a DLP Policy.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2747?
CVE-2015-2747 is classified as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2015-2747?
To mitigate CVE-2015-2747, upgrade to the latest version of Websense Triton or V-Series appliances that have patched the XSS vulnerabilities.
Which products are affected by CVE-2015-2747?
CVE-2015-2747 affects Websense Triton version 7.8.3 and Websense V-Series appliances version 7.7.
What types of attacks can CVE-2015-2747 facilitate?
CVE-2015-2747 can allow remote attackers to inject arbitrary web scripts or HTML via crafted emails or HTTP requests.
Is CVE-2015-2747 easy to exploit?
Yes, CVE-2015-2747 can be exploited by sending specially crafted input, making it a significant threat if not remediated.