CVE-2017-8801
MEDIUMTrend Micro OfficeScan 11.0 < SP1 CP 6325 and XG < CP 1352 - Cross-Site Scripting via Blocked Website URI
Title source: llmDescription
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
References (2)
Core 2
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://success.trendmicro.com/solution/1117204-security-bulletin-trend-micro-officescan-11-xg-multiple-vulnerabilities
Release Notes, Vendor Advisory x_refsource_confirm
http://files.trendmicro.com/products/officescan/11.0_SP1/readme/osce-11-sp1-patch1-win-all-criticalpatch-6325_readme.txt
Scores
CVSS v3
6.1
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
trendmicro/officescan
11.0
trendmicro/officescan
12.0
Published
May 05, 2017
Tracked Since
Feb 18, 2026