ZeroHour

CVE-2023-37360

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p30
Published
()
Modified
Description

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

Vendors
pacparser project
Products
pacparser
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.