CVE-2023-37360: Pacparser Project Pacparser
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
Affected products
- Pacparser Project Pacparser: before 1.4.2 (fixed in 1.4.2)
Published 2023-06-30. Last modified 2026-06-17.