Home
MEDIUM: 4.8 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
Description
Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version
Credits
Majchrowicz, Zdunek and Marcin Wyczechowski from AFINE Team.
References
support.forcepoint.com/...ripting-in-Forcepoint-Web-Security