Back to Database
Status published
High
CVE-2024-2166
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Vulnerability Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-2166
Credits & Attribution
No credits recorded in the NVD database.
More from Forcepoint
View All →CVE-2025-2274
Stored Cross Site Scripting in Forcepoint Web Security
Medium
4.8
CVE-2025-2272
Privilege Escalation and Arbitrary code execution in F1E Endpoint
High
7.3
CVE-2025-14026
Vulnerable Python version used in Forcepoint One DLP Client
Unknown
0
CVE-2025-12694
Local Privilege Escalation in VPN Client
High
8.5
CVE-2025-12690
Local Privilege Escalation in NGFW Engine
High
7.3
Affected Vendor
Forcepoint
View all reports →Affected Software
Email Security
Vulnerable Versions:
0
Timeline
Official Publish:
September 4th, 2024
Last Modified:
September 5th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H