CVE-2023-28799

EUVD-2023-32434
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
ZscalerCNA
8.2 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Affected Products (NVD)
VendorProductVersion
zscalerclient_connector
𝑥
< 1.4
zscalerclient_connector
𝑥
< 1.10.1
zscalerclient_connector
𝑥
< 3.7
zscalerclient_connector
𝑥
< 3.9
𝑥
= Vulnerable software versions
References