peter bassill · operator
$ cve CVE-2023-0214 JSON

CVE-2023-0214 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS1.89% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2023-01-18
Last modified2026-06-17

Affected (1)

VendorProduct
trellixskyhigh secure web gateway

Public exploits

SourceTitleDate
exploit-dbSecure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)2023-04-05

References

→ the Explorer  ·  watch your stack  ·  NVD