VulnerabilityModified
CVE-2018-15365
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations.
MEDIUM 5.4EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- trendmicro/deep discovery inspector
- Source
- security@trendmicro.com
References
- https://github.com/nixwizard/CVE-2018-15365/Exploit, Mitigation, Third Party Advisory
- https://success.trendmicro.com/solution/1121079Mitigation, Vendor Advisory
- https://github.com/nixwizard/CVE-2018-15365/Exploit, Mitigation, Third Party Advisory
- https://success.trendmicro.com/solution/1121079Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.