CVE-2023-28800
22.06.2023, 20:15
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
| Vendor | Product | Version |
|---|---|---|
| zscaler | client_connector | 𝑥 < 1.4 |
| zscaler | client_connector | 𝑥 < 1.10.1 |
| zscaler | client_connector | 𝑥 < 3.7 |
| zscaler | client_connector | 𝑥 < 3.9 |
𝑥
= Vulnerable software versions
References