A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trellix
Trellix central Management System |
|
| CPEs | cpe:2.3:a:trellix:central_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trellix
Trellix central Management System |
Status: PUBLISHED
Assigner: trellix
Published: 2024-02-13T09:39:54.600Z
Updated: 2025-04-24T15:39:35.589Z
Reserved: 2023-11-10T06:32:51.689Z
Link: CVE-2023-6072
Updated: 2024-08-02T08:21:17.153Z
Status : Modified
Published: 2024-02-13T10:15:08.227
Modified: 2024-11-21T08:43:05.313
Link: CVE-2023-6072
No data.