CVE-2024-0317
15.01.2024, 17:15
Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.
Vendor | Product | Version |
---|---|---|
fireeye | ex_5500_firmwarea | 9.0.3.936727 |
fireeye | ex_8500_firmware | 9.0.3.936727 |
fireeye | ex_3500_firmware | 9.0.3.936727 |
𝑥
= Vulnerable software versions