CVE-2018-15365
Last modified
CVE-2018-15365 is a vulnerability of currently unknown severity. A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Deep Discovery Inspector | <= 3.85 |
References
- https://github.com/nixwizard/CVE-2018-15365/Exploit, Mitigation, Third Party Advisory
- https://success.trendmicro.com/solution/1121079Mitigation, Vendor Advisory
- https://github.com/nixwizard/CVE-2018-15365/Exploit, Mitigation, Third Party Advisory
- https://success.trendmicro.com/solution/1121079Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15365?
How severe is CVE-2018-15365?
How do I fix CVE-2018-15365?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1536IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6…5.4
- CVE-2018-15360An attacker without authentication can login with default cr…
- CVE-2018-15361UltraVNC revision 1198 has a buffer underflow vulnerability …
- CVE-2018-15362XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0
- CVE-2018-15363An Out-of-Bounds Read Privilege Escalation vulnerability in …
- CVE-2018-15364A Named Pipe Request Processing Out-of-Bounds Read Informati…
- CVE-2018-15366A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalat…
- CVE-2018-15367A ctl_set KERedirect Untrusted Pointer Dereference Privilege…
- CVE-2018-15368A vulnerability in the CLI parser of Cisco IOS XE Software c…6.7
- CVE-2018-15369A vulnerability in the TACACS+ client subsystem of Cisco IOS…
- CVE-2018-15370A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software f…
- CVE-2018-15371A vulnerability in the shell access request mechanism of Cis…
Are you affected by CVE-2018-15365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
