Secure Web Gateway 10.2.11 Cross Site Scripting
Posted by deepcore on January 27, 2023 – 1:53 am
Last Updated on January 27, 2023 by deepcore
Secure Web Gateway version 10.2.11 suffers from a cross site scripting vulnerability. RedTeam Pentesting identified a vulnerability which allows attackers to craft URLs to any third-party website that result in arbitrary content to be injected into the response when accessed through the Secure Web Gateway. While it is possible to inject arbitrary content types, the primary risk arises from JavaScript code allowing for cross site scripting.
Post a reply
You must be logged in to post a comment.