Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability Affects Forcepoint Web Security
CVE-2023-6452
What is CVE-2023-6452?
A persistent Cross-Site Scripting (XSS) vulnerability exists in the Transaction Viewer of Forcepoint Web Security. This vulnerability allows attackers to exploit the 'user agent' field, which is improperly neutralized during web page generation. Administrators utilizing the Forcepoint Web Security portal may unknowingly execute malicious JavaScript in their browser context, enabling attackers to perform actions under the administrator’s authority. This presents significant risks, allowing unauthorized access and potential modifications within web security management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Web Security 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
