Medium severity6.1NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026
CVE-2019-6146
CVE-2019-6146
Description
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:forcepoint:web_security:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:forcepoint:web_security:*:*:*:*:*:*:*:*range: >=8.0.0,<8.5.4
- (no CPE)range: 8.x
- Forcepoint/Web Securitydescription
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/156274/Forcepoint-WebSecurity-8.5-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- help.forcepoint.com/security/CVE/CVE-2019-6146.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.