CVE-2023-28800: Output encoding missing in redrurl parameter
Published Jun 22, 2023
·Updated
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
Affected Software
6 affected components
Zscaler Client Connector Linux<1.4
Zscaler Client Connector Iphone Os<1.9.3
Zscaler Client Connector Chrome Os<1.10.1
Zscaler Client Connector Android<1.10.2
Zscaler Client Connector Windows<3.7
Zscaler Client Connector Macos<3.9
Event History
Jun 22, 2023
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
CVE-2023-28800
2
What is the severity level of CVE-2023-28800?
The severity level of CVE-2023-28800 is high.
3
Which software versions are affected by CVE-2023-28800?
Zscaler Client Connector versions 1.4 (Linux), 1.9.3 (iPhone OS), 1.10.1 (Chrome OS), 1.10.2 (Android), 3.7 (Windows), and 3.9 (macOS) are affected by CVE-2023-28800.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-28800?
The CWE ID for CVE-2023-28800 is CWE-79 and CWE-20.
5
How can I fix the vulnerability CVE-2023-28800?
To fix CVE-2023-28800, update to the latest version of Zscaler Client Connector that includes the necessary security patches.