CVE-2020-27018
PoC ×2—CVSS 3.1
5.5 medium
EPSS
4%p89
Published
()
Modified
Description
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.
- Vendors
- trendmicro
- Products
- interscan messaging security virtual appliance
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.