CVE-2023-41178

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41176.
Configurations

Configuration 1 (hide)

cpe:2.3:a:trendmicro:mobile_security:9.8:*:*:*:enterprise:*:*:*

History

29 Jan 2024, 17:35

Type Values Removed Values Added
First Time Trendmicro
Trendmicro mobile Security
CWE CWE-79
CPE cpe:2.3:a:trendmicro:mobile_security:9.8:*:*:*:enterprise:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://success.trendmicro.com/dcx/s/solution/000294695?language=en_US - () https://success.trendmicro.com/dcx/s/solution/000294695?language=en_US - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-24-080/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-080/ - Third Party Advisory, VDB Entry

24 Jan 2024, 13:49

Type Values Removed Values Added
Summary
  • (es) Las vulnerabilidades de cross-site scripting (XSS) reflejado en Trend Micro Mobile Security (Enterprise) podrían permitir una explotación contra una víctima autenticada que visita un enlace malicioso proporcionado por un atacante. Tenga en cuenta que esta vulnerabilidad es similar, pero no idéntica, a CVE-2023-41176.

23 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 21:15

Updated : 2024-01-29 17:35


NVD link : CVE-2023-41178

Mitre link : CVE-2023-41178

CVE.ORG link : CVE-2023-41178


JSON object : View

Products Affected

trendmicro

  • mobile_security
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')