PT-2024-15464 · Fireeye · Fireeye Central Management

Albert Sánchez Miñano

·

Published

2024-01-15

·

Updated

2024-01-19

·

CVE-2024-0314

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FireEye Central Management version 9.1.1.956704
Description The issue allows an attacker to modify special HTML elements in the application, causing a reflected XSS that could lead to session hijacking. This occurs because an attacker can modify these elements, allowing for the execution of malicious scripts.
Recommendations For version 9.1.1.956704, consider disabling any functionality that allows modification of special HTML elements until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of session hijacking.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0314

Affected Products

Fireeye Central Management