PT-2021-19403 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance
Published
2021-06-17
·
Updated
2021-06-21
·
CVE-2021-31521
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro InterScan Web Security Virtual Appliance version 6.5
Description
The issue is related to a reflected cross-site scripting (XSS) vulnerability found in the Captive Portal of the product. This type of vulnerability allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions on the user's session.
Recommendations
For Trend Micro InterScan Web Security Virtual Appliance version 6.5, consider disabling the Captive Portal feature until a patch is available to prevent potential exploitation of the reflected XSS vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Interscan Web Security Virtual Appliance