CVE-2023-0214
XSS in Skyhigh Security SWG
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.1EPSS 1.9%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
18 Jan 2023Published on NVD
05 Apr 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Skyhigh Security · Secure Web Gateway (SWG)public PoCs found — 2
githubgithub.com/0pts/CVE-2023-0214★ 0exploitdbwww.exploit-db.com/exploits/51237unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →