The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HProofpoint Enterprise Protection
APPProofpoint8.18.68.20.0< 8.13.228.18.0 – 8.18.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-0090CRITICAL9.8PL ✓same product
RCE przez eval injection w Proofpoint Enterprise Protection
CVE-2022-46332CRITICAL9.6PL ✓same product
Stored XSS w Proofpoint Enterprise Protection umożliwia eskalację uprawnień do admina
CVE-2022-46334HIGH7.8same product
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to r...
CVE-2022-46333HIGH7.2same product
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerabil...
CVE-2021-39304HIGH7.5same product
Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.