First published: Wed Mar 29 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_form.mhtml modules) allows Reflected XSS.This issue affects Cloud Security Gateway (CSG): before 03/29/2023; Web Security: before 03/29/2023.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Cloud Security Gateway | <2023-03-29 | |
Forcepoint Web Security | <2023-03-29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26291 is an improper neutralization of input vulnerability, also known as a Cross-site Scripting (XSS) vulnerability, in Forcepoint Cloud Security Gateway (CSG) Portal and Forcepoint Web Security Portal.
CVE-2023-26291 has a severity rating of 6.1, which is considered medium.
CVE-2023-26291 affects Forcepoint Cloud Security Gateway by allowing an attacker to execute malicious scripts on the CSG Portal, potentially leading to unauthorized access or manipulation of sensitive information.
CVE-2023-26291 affects Forcepoint Web Security Portal by allowing an attacker to execute malicious scripts on the Web Security Portal, potentially leading to unauthorized access or manipulation of sensitive information.
To fix CVE-2023-26291, it is recommended to apply the latest updates and patches provided by Forcepoint. Additionally, proper input validation and output encoding should be implemented to mitigate the risk of Cross-site Scripting (XSS) vulnerabilities.