First published: Wed Sep 13 2023(Updated: )
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
Credit: security@proofpoint.com security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Insider Threat Management | <7.14.3.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4802 is a reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console.
An authenticated administrator can use this vulnerability to run arbitrary JavaScript within another web console administrator's browser.
All versions prior to 7.14.3.69 of Proofpoint Insider Threat Management are affected by this vulnerability.
The severity of CVE-2023-4802 is medium with a CVSS score of 4.8.
To fix CVE-2023-4802, upgrade to version 7.14.3.69 or newer of Proofpoint Insider Threat Management.