First published: Fri May 30 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows remote authenticated users to inject arbitrary web script or HTML via the addWhiteListDomainStr parameter to addWhiteListDomain.imss.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro InterScan Messaging Security Virtual Appliance | =8.5.1.1516 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3922 is classified as a medium severity vulnerability due to its potential impact on user data.
To mitigate CVE-2014-3922, update Trend Micro InterScan Messaging Security Virtual Appliance to a version that does not contain this vulnerability.
CVE-2014-3922 affects remote authenticated users of Trend Micro InterScan Messaging Security Virtual Appliance version 8.5.1.1516.
CVE-2014-3922 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
The vulnerability in CVE-2014-3922 is exploited through the addWhiteListDomainStr parameter in the addWhiteListDomain.imss functionality.