Cross-Site Scripting Vulnerability in Trend Micro Apex Central
CVE-2023-32532

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2023

Summary

Certain dashboard widgets within the on-premise version of Trend Micro Apex Central are susceptible to cross-site scripting (XSS) attacks. An attacker exploiting this vulnerability can execute arbitrary scripts in the context of the user's session, potentially leading to unauthorized actions, data leakage, or remote code execution on compromised servers. Immediate remediation is advised to protect against these security risks.

Affected Version(s)

Trend Micro Apex Central 2019 (8.0) < 8.0.0.6394

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.