Generated remediation guidance and an executive summary. No account required.
A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent network to replace the image file with an arbitrary MIME type. This could result in arbitrary javascript code execution in an admin context. All versions prior to 5.10.0 are affected.
Cite this page
CVE-2023-2819. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-2819
Use CWE-79, Proofpoint vendor hub and Threat Response Auto Pull product page to widen CVE-2023-2819 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-2820 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.