Reflected Cross-Site Scripting Vulnerability in Trend Micro Apex Central
CVE-2023-32536
5.4MEDIUM
Summary
Trend Micro Apex Central (on-premise) is susceptible to reflected cross-site scripting (XSS) attacks due to inadequacies in user input validation and sanitization. This vulnerability requires an attacker to first authenticate to the system, making it paramount for users to implement robust access controls and regularly update their software to mitigate potential exploitation.
Affected Version(s)
Trend Micro Apex Central 2019 (8.0) < 8.0.0.6394
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved