First published: Tue Nov 05 2019(Updated: )
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevant hotfix in order to remediate this issue.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Email Security | =8.5 | |
Forcepoint Email Security | =8.5.3 | |
Forcepoint Security Manager | =8.5 | |
Forcepoint Security Manager | =8.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6142 is a vulnerability in Forcepoint Email Security versions 8.5 and 8.5.3 that allows for cross-site scripting (XSS) attacks.
The severity of CVE-2019-6142 is medium, with a severity value of 6.1.
To fix CVE-2019-6142, it is strongly recommended to apply the relevant hotfix provided by Forcepoint.
CVE-2019-6142 affects Forcepoint Email Security versions 8.5 and 8.5.3, as well as Forcepoint Security Manager versions 8.5 and 8.5.3.
The Common Weakness Enumeration (CWE) for CVE-2019-6142 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').