vendor:
Websense Email Security
by:
Nikolas Sotiriu
3.3
CVSS
LOW
Cross Site Scripting
79
CWE
Product Name: Websense Email Security
Affected Version From: Websense Email Security v7.1
Affected Version To: Websense Email Security v7.1
Patch Exists: Yes
Related CWE: N/A
CPE: a:websense:websense_email_security:7.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Websense Email Security Cross Site Scripting
The webfrontend of Websense Email Security software do not properly sanitize some variables before being returned to the user. This can lead to Cross Site Scripting (XSS) vulnerabilities.
Mitigation:
Websense Email Security v7.1 Hotfix 4 and Websense Personal Email Manager v7.1 Hotfix 4 are not affected by this vulnerability.