First published: Tue Dec 06 2022(Updated: )
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.
Credit: security@proofpoint.com security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Enterprise Protection | <=8.19.0 | |
<=8.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46332 is a stored cross-site scripting (XSS) vulnerability in the Admin Smart Search feature of Proofpoint Enterprise Protection (PPS/PoD) that allows an anonymous email sender to gain admin privileges within the user interface.
CVE-2022-46332 allows an anonymous email sender to exploit a stored XSS vulnerability in Proofpoint Enterprise Protection, enabling them to gain admin privileges in the user interface.
All versions of Proofpoint Enterprise Protection 8.19.0 and below are affected by CVE-2022-46332.
CVE-2022-46332 has a severity rating of 9.6 (Critical).
To fix CVE-2022-46332, it is recommended to upgrade Proofpoint Enterprise Protection to a version above 8.19.0.