PT-2024-14874 · Trellix · Trellix Central Management

Andrea Intilangelo

·

Published

2024-02-13

·

Updated

2024-10-07

·

CVE-2023-6072

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trellix Central Management versions prior to 9.1.3.97129
Description A cross-site scripting issue allows a remote authenticated attacker to craft internal requests to the CM dashboard, causing arbitrary content to be injected into the response when accessing the dashboard.
Recommendations For versions prior to 9.1.3.97129, update to version 9.1.3.97129 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-6072

Affected Products

Trellix Central Management