Cross-Site Scripting Vulnerability in Trend Micro ScanMail for Exchange
CVE-2017-14093

6.1MEDIUM

Key Information:

Vendor
CVE Published:
16 December 2017

Summary

The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 expose users to cross-site scripting (XSS) attacks. By manipulating these pages, an attacker could execute arbitrary JavaScript in the context of users' sessions, potentially stealing sensitive information or manipulating user actions. It is crucial for organizations using this product to apply the necessary patches and configurations to mitigate the risks associated with this vulnerability.

Affected Version(s)

Trend Micro ScanMail for Exchange 12.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.