Vulnerability Description
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proofpoint | Enterprise Protection | <= 8.19.0 |
Related Weaknesses (CWE)
References
- https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0002Vendor Advisory
- https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0002Vendor Advisory
FAQ
What is CVE-2022-46332?
CVE-2022-46332 is a vulnerability with a CVSS score of 9.6 (CRITICAL). The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within...
How severe is CVE-2022-46332?
CVE-2022-46332 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-46332?
Check the references section above for vendor advisories and patch information. Affected products include: Proofpoint Enterprise Protection.