vendor:
Web Security
by:
Prasenjit Kanti Paul
6.1
CVSS
MEDIUM
Reflective Cross-Site Scripting
79
CWE
Product Name: Web Security
Affected Version From: Forcepoint Web Security 8.5
Affected Version To: Forcepoint Web Security 8.5
Patch Exists: YES
Related CWE: CVE-2019-6146
CPE: a:forcepoint:web_security:8.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7,10 and Linux Mint
2019
Forcepoint WebSecurity 8.5 – Reflective Cross-Site Scripting
ForcePoint Web Security 8.5 is vulnerable to a reflective cross-site scripting vulnerability due to insufficient validation of the Host header. An attacker can exploit this vulnerability by intercepting the traffic while accessing a restricted website and modifying the Host header to inject malicious JavaScript code. This code will be executed in the context of the vulnerable website.
Mitigation:
ForcePoint KBA 000017702 provides a fix for this vulnerability.