Reflected Cross-Site Scripting Vulnerability in Trend Micro Apex Central
CVE-2023-32536

5.4MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2023

Summary

Trend Micro Apex Central (on-premise) is susceptible to reflected cross-site scripting (XSS) attacks due to inadequacies in user input validation and sanitization. This vulnerability requires an attacker to first authenticate to the system, making it paramount for users to implement robust access controls and regularly update their software to mitigate potential exploitation.

Affected Version(s)

Trend Micro Apex Central 2019 (8.0) < 8.0.0.6394

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.