Lucene search

K
zdiElias Martinez (filenotfound - https://www.linkedin.com/in/eli-martinez07/)ZDI-24-051
HistoryJan 11, 2024 - 12:00 a.m.

Trend Micro Apex Central Cross-Site Scripting Privilege Escalation Vulnerability

2024-01-1100:00:00
Elias Martinez (filenotfound - https://www.linkedin.com/in/eli-martinez07/)
www.zerodayinitiative.com
17
trend micro
apex central
cross-site scripting
privilege escalation
validation
policy management
user-supplied data
arbitrary script

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

49.0%

This vulnerability allows remote attackers to escalate privileges on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The specific flaw exists within the Policy Management functionality. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

49.0%

Related for ZDI-24-051