Vulnerability Description
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pacparser Project | Pacparser | < 1.4.2 |
Related Weaknesses (CWE)
References
- https://github.com/manugarg/pacparser/security/advisories/GHSA-62q6-v997-f7v9ExploitThird Party Advisory
- https://github.com/manugarg/pacparser/security/advisories/GHSA-62q6-v997-f7v9ExploitThird Party Advisory
FAQ
What is CVE-2023-37360?
CVE-2023-37360 is a vulnerability with a CVSS score of 5.9 (MEDIUM). pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security pro...
How severe is CVE-2023-37360?
CVE-2023-37360 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37360?
Check the references section above for vendor advisories and patch information. Affected products include: Pacparser Project Pacparser.