Reflected XSS Vulnerabilities in Trend Micro Email Encryption Gateway
CVE-2018-6226

5.4MEDIUM

Key Information:

Vendor
CVE Published:
15 March 2018

Summary

Reflected cross-site scripting (XSS) vulnerabilities have been identified in configuration files of Trend Micro Email Encryption Gateway 5.5. Attackers may exploit this flaw allowing them to inject malicious client-side scripts. Successful exploitation can lead to unauthorized access to sensitive information and potentially compromise user systems. It's crucial for users of the affected product to apply recommended mitigations and updates to safeguard against these vulnerabilities.

Affected Version(s)

Trend Micro Email Encryption Gateway 5.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.