Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5771

Опубликовано: 06 нояб. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages.  This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:*:*:*:*
Версия до 8.18.6 (исключая)
cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:-:*:*:*:*:*:*
cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:-:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00152
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 2 лет назад

Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages.  This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions.

EPSS

Процентиль: 36%
0.00152
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79