ZDI-23-654: Trend Micro Apex Central modTMMS SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-654?
The severity of ZDI-23-654 is high with a CVSS score of 7.2.
How can remote attackers exploit ZDI-23-654?
Remote attackers can exploit ZDI-23-654 by executing arbitrary code on affected installations of Trend Micro Apex Central, but authentication is required.
What is the affected software by ZDI-23-654?
The affected software is Trend Micro Apex Central.
How can I fix ZDI-23-654?
To fix ZDI-23-654, follow the recommendations provided by Trend Micro in their solution article, available at https://success.trendmicro.com/solution/000293107.
Where can I find more information about ZDI-23-654?
You can find more information about ZDI-23-654 in the advisory published by Zero Day Initiative at http://www.zerodayinitiative.com/advisories/ZDI-23-654/.