CVE-2018-15365: XSS
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15365?
CVE-2018-15365 is a Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below.
How does CVE-2018-15365 affect Trend Micro Deep Discovery Inspector?
CVE-2018-15365 allows an attacker to bypass CSRF protection and conduct an attack on vulnerable installations of Trend Micro Deep Discovery Inspector 3.85 and below.
What is the severity of CVE-2018-15365?
CVE-2018-15365 has a severity rating of medium with a CVSS score of 5.4.
How can an attacker exploit CVE-2018-15365?
To exploit CVE-2018-15365, an attacker must be an authenticated user and can then perform a Reflected Cross-Site Scripting (XSS) attack on the vulnerable installations.
Is there a fix for CVE-2018-15365?
Yes, Trend Micro has released a solution to address the CVE-2018-15365 vulnerability. Please refer to the provided reference links for more details.