First published: Fri May 05 2017(Updated: )
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan | =11.0 | |
Trend Micro OfficeScan | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8801 has been classified as a medium severity vulnerability.
To fix CVE-2017-8801, upgrade Trend Micro OfficeScan to version 11.0 SP1 CP 6325 or higher.
CVE-2017-8801 allows for cross-site scripting (XSS) attacks via crafted URIs.
CVE-2017-8801 affects Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352.
Yes, successful exploitation of CVE-2017-8801 could potentially lead to unauthorized access and data breaches.