[RT-SA-2022-002] Skyhigh Security Secure Web Gateway: Cross-Site Scripting in Single

jn1122

Well-known member
Member
Joined
11 yrs. 6 mth. 19 days
Messages
668
Reaction score
0
Wallet
0$
[RT-SA-2022-002] Skyhigh Security Secure Web Gateway: Cross-Site Scripting in Single

<p>Posted by RedTeam Pentesting GmbH on Jan 26</p>RedTeam Pentesting identified a vulnerability which allows attackers to<br>
craft URLs to any third-party website that result in arbitrary content<br>
to be injected into the response when accessed through the Secure Web<br>
Gateway. While it is possible to inject arbitrary content types, the<br>
primary risk arises from JavaScript code allowing for cross-site<br>
scripting.<br>
<br>
Details<br>
=======<br>
<br>
Product: Secure Web Gateway<br>
Affected Versions: 10.2.11, potentially other...<br>


Please, Log in or Register to view URLs content!
 
Top Bottom