CVE-2017-8801Cross-site Scripting in Officescan

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 44.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5
Latest updateMay 17

Description

Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDtrendmicro/officescan11.0, 12.0+1

🔴Vulnerability Details

2
GHSA
GHSA-wmv2-95fh-hx2w: Trend Micro OfficeScan 112022-05-17
CVEList
CVE-2017-8801: Trend Micro OfficeScan 112017-05-05
CVE-2017-8801 — Cross-site Scripting in Trendmicro | cvebase