6.1
CVSSv3

CVE-2023-37360

Published: 30/06/2023 Updated: 07/07/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

pacparser_find_proxy in Pacparser prior to 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

Vulnerable Product Search on Vulmon Subscribe to Product

pacparser project pacparser

Vendor Advisories

Debian Bug report logs - #1041425 pacparser: CVE-2023-37360 Package: src:pacparser; Maintainer for src:pacparser is Manu Garg <manugarg@gmailcom>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 18 Jul 2023 18:45:05 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug To ...