CVE-2017-9037

Severity
6.1MEDIUM
EPSS
1.2%
top 20.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateMay 13

Description

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8) T117117, (9) T118, (10) T_action_fail, (11) T_ptn_update, (12) textarea, (13) textfield5, or (14) tmLastConfigFileModifiedDate parameter to notification.cgi.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rc45-jq3j-7rr5: Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 32022-05-13
CVEList
CVE-2017-9037: Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 32017-05-25
CVE-2017-9037 (MEDIUM CVSS 6.1) | Multiple cross-site scripting (XSS) | cvebase.io