NA

CVE-2023-0214

Published: 18/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x before 11.2.6, 10.x before 10.2.17, and controlled release 12.x before 12.0.1 allows a remote malicious user to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trellix skyhigh secure web gateway 12.0.0

trellix skyhigh secure web gateway

Exploits

Secure Web Gateway version 10211 suffers from a cross site scripting vulnerability RedTeam Pentesting identified a vulnerability which allows attackers to craft URLs to any third-party website that result in arbitrary content to be injected into the response when accessed through the Secure Web Gateway While it is possible to inject arbitrary c ...