First published: Wed Mar 29 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules) allows Reflected XSS.This issue affects Cloud Security Gateway (CSG): before 03/29/2023; Web Security: before 03/29/2023.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Cloud Security Gateway | <2023-03-29 | |
Forcepoint Web Security | <2023-03-29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26292 is an 'Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)' vulnerability found in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), and Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules).
CVE-2023-26292 has a severity level of 6.1, which is considered medium.
CVE-2023-26292 allows for Cross-site Scripting (XSS) attacks on the Forcepoint Cloud Security Gateway by improperly neutralizing input during web page generation.
CVE-2023-26292 allows for Cross-site Scripting (XSS) attacks on the Forcepoint Web Security Portal by improperly neutralizing input during web page generation.
You can find more information about CVE-2023-26292 in the Forcepoint support article: https://support.forcepoint.com/s/article/000041617