CVE-2023-37360: Pacparser Project Pacparser

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

Affected products

Published 2023-06-30. Last modified 2026-06-17.