CVE-2019-6146

MEDIUM

Forcepoint Web Security 8.0.0-8.5.3 - Cross-Site Scripting via Host Header Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-6146. PoCs published by Prasenjit Kanti Paul.

AI-analyzed exploit summary This is a technical writeup describing a reflective XSS vulnerability in Forcepoint Web Security 8.5, where the Host header is not properly validated in the blocking page, allowing injection of malicious scripts.

Description

It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Exploits (1)

exploitdb WRITEUP
by Prasenjit Kanti Paul · textwebappsmultiple
https://www.exploit-db.com/exploits/48029

This is a technical writeup describing a reflective XSS vulnerability in Forcepoint Web Security 8.5, where the Host header is not properly validated in the blocking page, allowing injection of malicious scripts.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Forcepoint Web Security 8.5
No auth needed
Prerequisites: User must visit a restricted site to trigger the blocking page
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References

Scores

CVSS v3 6.1
EPSS 0.0298
EPSS Percentile 85.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
forcepoint/web_security 8.0.0 - 8.5.4
Published Jan 22, 2020
Tracked Since Feb 18, 2026