CVE-2017-6340

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages.
References
Link Resource
https://www.qualys.com/2017/01/12/qsa-2017-01-12/qsa-2017-01-12.pdf Exploit Technical Description Third Party Advisory
https://success.trendmicro.com/solution/1116960 Patch Vendor Advisory
http://www.securityfocus.com/bid/97487 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:*:*:*:*:*:*:*:*

Information

Published : 2017-04-05 09:59

Updated : 2017-04-11 12:23


NVD link : CVE-2017-6340

Mitre link : CVE-2017-6340


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

trendmicro

  • interscan_web_security_virtual_appliance