Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
Published: 2024-09-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27130 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
History

Thu, 12 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:forcepoint:email_security:8.5.5:-:*:*:*:*:*:*

Thu, 05 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Forcepoint
Forcepoint email Security
CPEs cpe:2.3:a:forcepoint:email_security:*:*:*:*:*:*:*:*
Vendors & Products Forcepoint
Forcepoint email Security
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Forcepoint Email Security
cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2024-09-05T14:23:10.788Z

Reserved: 2024-03-04T15:39:26.796Z

Link: CVE-2024-2166

cve-icon Vulnrichment

Updated: 2024-09-05T14:22:57.471Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-04T22:15:04.260

Modified: 2024-09-12T17:19:43.607

Link: CVE-2024-2166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses