Medium severity4.6NVD Advisory· Published Feb 13, 2024· Updated Jun 17, 2026
CVE-2023-6072
CVE-2023-6072
Description
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
Affected products
3- cpe:2.3:a:trellix:central_management_system:*:*:*:*:*:*:*:*Range: <9.1.3.97129
<9.1.3.97129+ 1 more
- (no CPE)range: <9.1.3.97129
- (no CPE)range: Prior to 9.1.3.97129
Patches
Vulnerability mechanics
References
1- docs.trellix.com/bundle/cm_9-1-5_rn/page/UUID-fad8a50f-6f6f-e970-f418-06494a30932e.htmlnvdPermissions Required
News mentions
0No linked articles in our index yet.