Cross-Site Scripting Vulnerability in Trend Micro ScanMail for Exchange
CVE-2017-14093
6.1MEDIUM
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 16 December 2017
Summary
The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 expose users to cross-site scripting (XSS) attacks. By manipulating these pages, an attacker could execute arbitrary JavaScript in the context of users' sessions, potentially stealing sensitive information or manipulating user actions. It is crucial for organizations using this product to apply the necessary patches and configurations to mitigate the risks associated with this vulnerability.
Affected Version(s)
Trend Micro ScanMail for Exchange 12.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved