Filtered by vendor Zscaler Subscriptions
Filtered by product Client Connector Subscriptions
Total 28 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-28799 1 Zscaler 1 Client Connector 2024-08-02 8.2 High
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain. 
CVE-2023-28800 1 Zscaler 1 Client Connector 2024-08-02 8.1 High
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
CVE-2023-28793 1 Zscaler 1 Client Connector 2024-08-02 7.8 High
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
CVE-2023-28795 1 Zscaler 1 Client Connector 2024-08-02 7.8 High
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
CVE-2023-28797 1 Zscaler 1 Client Connector 2024-08-02 6.3 Medium
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.
CVE-2023-28805 1 Zscaler 1 Client Connector 2024-08-02 6.7 Medium
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105
CVE-2023-28798 1 Zscaler 1 Client Connector 2024-08-02 6.5 Medium
An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.
CVE-2023-28802 1 Zscaler 1 Client Connector 2024-08-02 4.9 Medium
An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149.