CVE-2023-6452

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows administrators to generate detailed reports on user requests made through the Web proxy. It has been determined that the "user agent" field in the Transaction Viewer is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability, which can be exploited by any user who can route traffic through the Forcepoint Web proxy. This vulnerability enables unauthorized attackers to execute JavaScript within the browser context of a Forcepoint administrator, thereby allowing them to perform actions on the administrator's behalf. Such a breach could lead to unauthorized access or modifications, posing a significant security risk. This issue affects Web Security: before 8.5.6.

Remediation

Solution:

  • Customers should update to version 8.5.6 or follow the steps outlined in  https://support.forcepoint.com/s/article/000042212  for version 8.5.5.

Workaround:

  • Users should avoid adding the User Agent field to the Transaction Viewer until the workaround is implemented or Web Security is upgraded to version 8.5.6 or later.

Category

9.6
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 0.10%
Affected: Forcepoint Web Security
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-6452?
CVE-2023-6452 has been scored as a critical severity vulnerability.
How to fix CVE-2023-6452?
To fix CVE-2023-6452: Customers should update to version 8.5.6 or follow the steps outlined in  https://support.forcepoint.com/s/article/000042212  for version 8.5.5.
Is CVE-2023-6452 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-6452 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-6452?
CVE-2023-6452 affects Forcepoint Web Security.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.