Описание
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
Ссылки
- ExploitMitigationThird Party Advisory
- MitigationVendor Advisory
- ExploitMitigationThird Party Advisory
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.85 (включая)
cpe:2.3:a:trendmicro:deep_discovery_inspector:*:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.00602
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
EPSS
Процентиль: 69%
0.00602
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79