Vulnerability Description
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Officescan | 11.0 |
Related Weaknesses (CWE)
References
- http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patcRelease NotesVendor Advisory
- https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-ofMitigationVendor Advisory
- http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patcRelease NotesVendor Advisory
- https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-ofMitigationVendor Advisory
FAQ
What is CVE-2017-8801?
CVE-2017-8801 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
How severe is CVE-2017-8801?
CVE-2017-8801 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8801?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Officescan.