CVE-2023-5771 – HTML injection in AdminUI through email subject
https://notcve.org/view.php?id=CVE-2023-5771
06 Nov 2023 — Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages. This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions. Proofpoint Enterprise Protection contiene una vulnerabilidad XSS almacenada en AdminUI. Un atacante no autenticado puede enviar un correo ele... • https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0010 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-0090 – Proofpoint Enterprise Protection webservices unauthenticated RCE
https://notcve.org/view.php?id=CVE-2023-0090
08 Mar 2023 — The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below. • https://www.proofpoint.com/security/security-advisories/pfpt-sa-2023-0001 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') •
CVE-2023-0089 – Proofpoint Enterprise Protection webutils authenticated RCE
https://notcve.org/view.php?id=CVE-2023-0089
08 Mar 2023 — The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below. • https://www.proofpoint.com/security/security-advisories/pfpt-sa-2023-0001 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') •
CVE-2022-46334 – Proofpoint Enterprise Protection Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2022-46334
21 Dec 2022 — Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below. Proofpoint Enterprise Protection (PPS/PoD) contiene una vulnerabilidad que permite al usuario de pps escalar a privilegios de root debido a permisos innecesarios. Esto afecta a todas las versiones 8.19.0 y anteriores. • https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0004 • CWE-269: Improper Privilege Management •
CVE-2022-46333 – Proofpoint Enterprise Protection perl eval() arbitrary command execution
https://notcve.org/view.php?id=CVE-2022-46333
06 Dec 2022 — The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below. La interfaz de usuario administrador en Proofpoint Enterprise Protection (PPS/PoD) contiene una vulnerabilidad de inyección de comandos que permite a un administrador ejecutar comandos más allá de su alcance permitido. Esto afecta a todas las versiones 8.19.0 y anteriores. • https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0003 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2022-46332 – Proofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"
https://notcve.org/view.php?id=CVE-2022-46332
06 Dec 2022 — The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below. La función Admin Smart Search en Proofpoint Enterprise Protection (PPS/PoD) contiene una vulnerabilidad de cross-site scripting almacenado que permite a un remitente de correo electrónico anónimo obtener privilegios de administrador dentro de la i... • https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0002 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-31608
https://notcve.org/view.php?id=CVE-2021-31608
17 Nov 2022 — Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. Proofpoint Enterprise Protection anterior a 18.8.0 permite omitir un control de seguridad. • https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0011 •
CVE-2021-39304
https://notcve.org/view.php?id=CVE-2021-39304
13 Oct 2021 — Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass. Proofpoint Enterprise Protection versiones anteriores a 8.12.0-2108090000 permite una omisión del control de seguridad • https://www.proofpoint.com/us/blog •
CVE-2020-14009
https://notcve.org/view.php?id=CVE-2020-14009
07 May 2021 — Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled. Proofpoint Enterprise Protection (PPS/PoD) versiones anteriores a 8.16.4, contiene una vulnerabilidad que podría permitir a un atacante entregar un mensaje de correo electró... • https://www.proofpoint.com/us/security/security-advisories • CWE-354: Improper Validation of Integrity Check Value •
CVE-2019-19680
https://notcve.org/view.php?id=CVE-2019-19680
13 Jan 2020 — A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email. Una vulnerabilidad de filtrado de extensiones de archivos en Proofpoint Enterprise Protection (PPS / PoD), en las versiones sin parches de PPS a t... • https://www.proofpoint.com/us/security/cve-2019-19680 •