PT-2021-19403 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Published

2021-06-17

·

Updated

2021-06-21

·

CVE-2021-31521

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Web Security Virtual Appliance version 6.5
Description The issue is related to a reflected cross-site scripting (XSS) vulnerability found in the Captive Portal of the product. This type of vulnerability allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions on the user's session.
Recommendations For Trend Micro InterScan Web Security Virtual Appliance version 6.5, consider disabling the Captive Portal feature until a patch is available to prevent potential exploitation of the reflected XSS vulnerability.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31521

Affected Products

Trend Micro Interscan Web Security Virtual Appliance