SQL Injection Vulnerability in Forcepoint Cloud Security Gateway Portal
CVE-2023-2080

8.5HIGH

Key Information:

Vendor

Forcepoint

Vendor
CVE Published:
15 June 2023

What is CVE-2023-2080?

The Forcepoint Cloud Security Gateway Portal is susceptible to an SQL Injection vulnerability that allows attackers to manipulate SQL queries. This flaw enables blind SQL injection attacks, potentially leading to unauthorized access or disclosure of sensitive information stored in the database. The issue arises from improper neutralization of special elements in SQL commands, emphasizing the need for robust input validation to safeguard against such security threats.

Affected Version(s)

Cloud Security Gateway (CSG) Web Cloud Security Gateway TBD

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.