VYPR
Medium severity6.1NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026

CVE-2019-6146

CVE-2019-6146

Description

It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:forcepoint:web_security:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:forcepoint:web_security:*:*:*:*:*:*:*:*range: >=8.0.0,<8.5.4
    • (no CPE)range: 8.x
  • Forcepoint/Web Securitydescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.