NA

CVE-2023-41717

Published: 31/08/2023 Updated: 07/09/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local malicious users to bypass file download/upload restrictions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zscaler zscaler proxy

Github Repositories

This repository is to provide a write-up and PoC for CVE-2023-41717.

CVE-2023-41717 Inappropriate file type control in Zscaler Proxy versions 36125 and prior allows local attackers to bypass file download/upload restrictions Executive Summary During the summer of 2022, I have found a vulnerability affecting the ZScaler proxy (versions 36125 and prior) This vulnerability would allow local attackers to bypass the restriction on downloads/u