PT-2024-1470 · Fireeye · Fireeye Ex
Albert Sánchez Miñano
·
Published
2024-01-15
·
Updated
2024-01-30
·
CVE-2024-0317
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FireEye EX version 9.0.3.936727
Description
The issue is related to Cross-Site Scripting (XSS) in FireEye EX. An attacker can exploit this by sending a specially crafted JavaScript payload via the
type and s f name parameters to an authenticated user, allowing them to retrieve the user's session details.Recommendations
For FireEye EX version 9.0.3.936727, as a temporary workaround, consider disabling the use of the
type and s f name parameters until a patch is available. Restrict access to authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fireeye Ex