First published: Wed Sep 13 2023(Updated: )
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
Credit: security@proofpoint.com security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Insider Threat Management | <7.14.3.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-4803.
The severity of CVE-2023-4803 is medium.
The affected software by CVE-2023-4803 is Proofpoint Insider Threat Management versions prior to 7.14.3.69.
An attacker can exploit CVE-2023-4803 by using a reflected cross-site scripting attack in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console.
Yes, a fix is available for CVE-2023-4803. It is recommended to update Proofpoint Insider Threat Management to version 7.14.3.69 or later.