MEDIUM
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe
Published Aug 23, 2012
4.3
MEDIUMCVSS 2.0
EPSS 1.34%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.