CVE-2023-28800: Zscaler Client Connector

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

Affected products

  • Zscaler Client Connector: before 1.4 (fixed in 1.4); before 1.9.3 (fixed in 1.9.3); before 1.10.1 (fixed in 1.10.1); before 1.10.2 (fixed in 1.10.2); before 3.7 (fixed in 3.7); before 3.9 (fixed in 3.9)

Published 2023-06-22. Last modified 2026-06-17.