CVE-2018-15365
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
Affected (1)
Products: Trendmicro: Deep Discovery Inspector
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.85 |
References (4)
Source: security@trendmicro.com
ExploitMitigationThird Party Advisory
Source: security@trendmicro.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.