First published: Wed Mar 29 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules) allows Reflected XSS.This issue affects Cloud Security Gateway (CSG): before 03/29/2023; Web Security: before 03/29/2023.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Cloud Security Gateway | <2023-03-29 | |
Forcepoint Web Security | <2023-03-29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26290 is an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal and Forcepoint Web Security Portal.
CVE-2023-26290 has a severity of 6.1 (medium).
CVE-2023-26290 affects Forcepoint Cloud Security Gateway (CSG) Portal and Forcepoint Web Security Portal.
Cross-site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To fix CVE-2023-26290, it is recommended to apply the necessary patches or updates provided by Forcepoint.