Vulnerabilities > Proofpoint > Insider Threat Management > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-4802 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser.
network
low complexity
proofpoint CWE-79
4.8
2023-09-13 CVE-2023-4803 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser.
network
low complexity
proofpoint CWE-79
4.8
2023-09-13 CVE-2023-4828 Improper Check for Unusual or Exceptional Conditions vulnerability in Proofpoint Insider Threat Management
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL.
network
high complexity
proofpoint CWE-754
4.2
2023-06-27 CVE-2023-2818 Improper Preservation of Permissions vulnerability in Proofpoint Insider Threat Management
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring.
local
low complexity
proofpoint CWE-281
5.5
2021-04-06 CVE-2021-22157 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
network
low complexity
proofpoint CWE-79
6.1