ITM Server Cross-site Scripting in UpdateInstalledSoftware Endpoint
Vulnerability Description
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4802
Credits & Attribution
No credits recorded in the NVD database.
More from Proofpoint
View All →Affected Vendor
Proofpoint
View all reports →