First published: Thu Jun 15 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Email Security | ||
Forcepoint Web Security |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-2080.
The title of the vulnerability is 'Improper Neutralization of Special Elements used in an SQL Command ( SQL Injection ).'
CVE-2023-2080 has a severity of critical.
Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud is affected by CVE-2023-2080.
The SQL Injection vulnerability in Forcepoint Cloud Security Gateway can be exploited through improper neutralization of special elements used in an SQL command.
Please refer to the following link for information on available fixes: [https://support.forcepoint.com/s/article/000041871](https://support.forcepoint.com/s/article/000041871)
The CWE ID for CVE-2023-2080 is 89.