{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-2080","assignerOrgId":"e23ea22c-8c39-4eff-8980-2881e5ae54e2","state":"PUBLISHED","assignerShortName":"forcepoint","dateReserved":"2023-04-14T19:12:38.266Z","datePublished":"2023-06-15T22:18:58.058Z","dateUpdated":"2024-12-11T20:33:35.315Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"Portal","platforms":["Web Cloud Security Gateway","Email Security Cloud"],"product":"Cloud Security Gateway (CSG) ","vendor":"Forcepoint","versions":[{"status":"unaffected","version":"TBD"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection."}],"value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection."}],"impacts":[{"capecId":"CAPEC-7","descriptions":[{"lang":"en","value":"CAPEC-7 Blind SQL Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"e23ea22c-8c39-4eff-8980-2881e5ae54e2","shortName":"forcepoint","dateUpdated":"2023-06-15T22:18:58.058Z"},"references":[{"url":"https://support.forcepoint.com/s/article/000041871"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T06:12:19.936Z"},"title":"CVE Program Container","references":[{"url":"https://support.forcepoint.com/s/article/000041871","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-12-11T20:33:24.376436Z","id":"CVE-2023-2080","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-12-11T20:33:35.315Z"}}]}}