A cross-site scripting vulnerability has been found in iboss Secure Web Gateway up to version 10.1. The vulnerability affects the /login file of the Login Portal component, where manipulation of the redirectUrl parameter leads to cross-site scripting. The attack can be launched remotely and the exploit has been disclosed to the public.
id: CVE-2024-3378
info:
name: iboss Secure Web Gateway - Stored Cross-Site Scripting
author: s4
...