CVE-2019-6146
MEDIUMForcepoint Web Security 8.0.0-8.5.3 - Cross-Site Scripting via Host Header Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6146. PoCs published by Prasenjit Kanti Paul.
AI-analyzed exploit summary This is a technical writeup describing a reflective XSS vulnerability in Forcepoint Web Security 8.5, where the Host header is not properly validated in the blocking page, allowing injection of malicious scripts.
Description
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploits (1)
This is a technical writeup describing a reflective XSS vulnerability in Forcepoint Web Security 8.5, where the Host header is not properly validated in the blocking page, allowing injection of malicious scripts.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N