CVE detail
CVE-2019-6146 — CVE-2019-6146
Published 2020-01-22 · Modified 2026-06-17 · Vendor forcepoint · Product web_security · Source nvd
MEDIUM
severity
CVSS-derived band
0.0298
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References