ZeroHour

CVE-2023-28800

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

Vendors
zscaler
Products
client connector
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.