PT-2024-14874 · Trellix · Trellix Central Management

·

CVE-2023-6072

·

Published

2024-02-13

·

Updated

2024-10-07

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trellix Central Management versions prior to 9.1.3.97129
Description A cross-site scripting issue allows a remote authenticated attacker to craft internal requests to the CM dashboard, causing arbitrary content to be injected into the response when accessing the dashboard.
Recommendations For versions prior to 9.1.3.97129, update to version 9.1.3.97129 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6072

Affected Products

Trellix Central Management