Secure Web Gateway 10.2.11 Cross Site Scripting
Posted by deepcore on January 27, 2023 – 1:53 am
Secure Web Gateway version 10.2.11 suffers from a cross site scripting vulnerability. RedTeam Pentesting identified a vulnerability which allows attackers to craft URLs to any third-party website that result in arbitrary content to be injected into the response when accessed through the Secure Web Gateway. While it is possible to inject arbitrary content types, the primary risk arises from JavaScript code allowing for cross site scripting.
Post a reply
You must be logged in to post a comment.