CVE-2017-8801: XSS
Published May 5, 2017
·Updated
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
Affected Software
2 affected components
trendmicro Officescan=11.0
trendmicro Officescan=12.0
Event History
May 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8801?
CVE-2017-8801 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-8801?
To fix CVE-2017-8801, upgrade Trend Micro OfficeScan to version 11.0 SP1 CP 6325 or higher.
3
What types of attacks are possible with CVE-2017-8801?
CVE-2017-8801 allows for cross-site scripting (XSS) attacks via crafted URIs.
4
Which versions of Trend Micro OfficeScan are affected by CVE-2017-8801?
CVE-2017-8801 affects Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352.
5
Can exploiting CVE-2017-8801 lead to data breaches?
Yes, successful exploitation of CVE-2017-8801 could potentially lead to unauthorized access and data breaches.