First published: Mon Nov 06 2023(Updated: )
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages. This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions.
Credit: security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Enterprise Protection | <8.18.6 | |
Proofpoint Enterprise Protection | =8.18.6 | |
Proofpoint Enterprise Protection | =8.20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5771 is a vulnerability that allows an unauthenticated attacker to execute HTML injection in Proofpoint Enterprise Protection AdminUI through email subject.
CVE-2023-5771 affects Proofpoint Enterprise Protection versions 8.18.6 and 8.20.0 by allowing an unauthenticated attacker to send a specially crafted email with HTML in the subject, triggering XSS when viewing quarantined messages.
CVE-2023-5771 has a severity rating of 6.1 (medium).
To fix CVE-2023-5771, upgrade Proofpoint Enterprise Protection to a version after 8.20.0.
More information about CVE-2023-5771 can be found at the following reference link: [Proofpoint Security Advisory](https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0010).