CVE-2022-46332 CRITICAL

CVE-2022-46332: Proofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"

Vendor Proofpoint
Product enterprise_protection
Weakness CWE-79 · XSS
Published December 6, 2022
Last update April 23, 2025

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.

Key dates

02Disclosure timeline

December 6, 2022 CVE published
April 23, 2025 Record updated