CVE-2023-28799: Zscaler Client Connector
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
Affected products
- Zscaler Client Connector: before 1.4 (fixed in 1.4); before 1.9.3 (fixed in 1.9.3); before 1.10.1 (fixed in 1.10.1); before 1.10.2 (fixed in 1.10.2); before 3.7 (fixed in 3.7); before 3.9 (fixed in 3.9)
Published 2023-06-22. Last modified 2026-06-17.