pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
History

Tue, 26 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-06-30T00:00:00

Updated: 2024-11-26T16:13:54.841Z

Reserved: 2023-06-30T00:00:00

Link: CVE-2023-37360

cve-icon Vulnrichment

Updated: 2024-08-02T17:09:34.275Z

cve-icon NVD

Status : Modified

Published: 2023-06-30T18:15:10.420

Modified: 2024-11-21T08:11:34.787

Link: CVE-2023-37360

cve-icon Redhat

No data.