First published: Thu Mar 15 2018(Updated: )
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Email Encryption Gateway | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6226 is classified as a reflected cross-site scripting (XSS) vulnerability with a potential impact on client-side execution.
To fix CVE-2018-6226, update the Trend Micro Email Encryption Gateway to the latest version that addresses this vulnerability.
CVE-2018-6226 affects the Trend Micro Email Encryption Gateway version 5.5.
Yes, CVE-2018-6226 can be exploited remotely as it involves injecting scripts through vulnerable configuration files.
CVE-2018-6226 can facilitate various attacks such as session hijacking and redirecting users to malicious websites.