First published: Mon Jan 15 2024(Updated: )
XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
FireEye Central Management | =9.1.1.956704 |
The FireEye team is working on fixing the reported vulnerabilities. It is recommended to update affected products to the latest version available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0314 is classified as a moderate severity XSS vulnerability.
To fix CVE-2024-0314, upgrade FireEye Central Management to the latest version that addresses this vulnerability.
CVE-2024-0314 is caused by improper handling of HTML elements, allowing reflected XSS attacks.
CVE-2024-0314 affects users of FireEye Central Management version 9.1.1.956704.
CVE-2024-0314 could lead to session hijacking due to reflected XSS vulnerabilities.