Stored Cross-Site Scripting Vulnerability in Trend Micro Email Encryption Gateway
CVE-2018-6227

5.4MEDIUM

Key Information:

Vendor
CVE Published:
15 March 2018

Summary

The vulnerability in Trend Micro Email Encryption Gateway 5.5 enables attackers to leverage stored cross-site scripting techniques, allowing them to inject malicious client-side scripts into the application. This flaw can be exploited if the input is not properly sanitized, presenting significant risks to users who interact with the compromised system. Successful exploitation may lead to unauthorized actions performed on behalf of victims and the potential exposure of sensitive information.

Affected Version(s)

Trend Micro Email Encryption Gateway 5.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.