← Back

CVE-2018-15365

nvd nist
Published: Sep 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.

Affected (1)

1 product
Deep Discovery Inspector
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.85

References (4)

Source: security@trendmicro.com
ExploitMitigationThird Party Advisory
Source: security@trendmicro.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.