Vulnerability Description
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trellix | Central Management System | < 9.1.3.97129 |
Related Weaknesses (CWE)
References
- https://docs.trellix.com/bundle/cm_9-1-5_rn/page/UUID-fad8a50f-6f6f-e970-f418-06Permissions Required
- https://docs.trellix.com/bundle/cm_9-1-5_rn/page/UUID-fad8a50f-6f6f-e970-f418-06Permissions Required
FAQ
What is CVE-2023-6072?
CVE-2023-6072 is a vulnerability with a CVSS score of 4.6 (MEDIUM). A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content t...
How severe is CVE-2023-6072?
CVE-2023-6072 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6072?
Check the references section above for vendor advisories and patch information. Affected products include: Trellix Central Management System.