SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28800

When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

MEDIUM 6.1EPSS 0.55%

Does this matter?

Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.

Description

When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.55% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zscaler/client connector
Source
cve@zscaler.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.