PT-2024-12927 · Trend Micro · Trend Micro Mobile Security
Poh Jia Hao
·
Published
2024-01-19
·
Updated
2024-01-29
·
CVE-2023-41178
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Mobile Security (Enterprise) (affected versions not specified)
Description
The issue is related to reflected cross-site scripting (XSS) vulnerabilities, which could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. This vulnerability enables remote attackers to execute web requests with the victim's privileges on affected installations. User interaction is required for the exploitation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Mobile Security