vendor:
PortWise SSL VPN
by:
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: PortWise SSL VPN
Affected Version From: 4.6
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Cross-Site Scripting Vulnerability in PortWise SSL VPN
The PortWise SSL VPN is vulnerable to a cross-site scripting (XSS) attack due to inadequate input sanitization. An attacker can exploit this vulnerability to inject and execute arbitrary script code in the browser of a targeted user, within the context of the affected site. This can lead to the theft of cookie-based authentication credentials and enable the attacker to launch further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of PortWise SSL VPN or apply any available security patches provided by the vendor. Additionally, input validation and sanitization should be implemented to prevent XSS attacks.