Vulnerability Description
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proofpoint | Insider Threat Management | < 7.14.3.69 |
Related Weaknesses (CWE)
References
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-007Broken Link
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0007Vendor Advisory
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-007Broken Link
FAQ
What is CVE-2023-4803?
CVE-2023-4803 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbit...
How severe is CVE-2023-4803?
CVE-2023-4803 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4803?
Check the references section above for vendor advisories and patch information. Affected products include: Proofpoint Insider Threat Management.