XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16110 | XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking. |
Fixes
Solution
The FireEye team is working on fixing the reported vulnerabilities. It is recommended to update affected products to the latest version available.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-03T14:00:17.084Z
Reserved: 2024-01-08T11:55:59.441Z
Link: CVE-2024-0314
Updated: 2024-08-01T18:04:48.586Z
Status : Modified
Published: 2024-01-15T16:15:12.793
Modified: 2024-11-21T08:46:18.317
Link: CVE-2024-0314
No data.
OpenCVE Enrichment
No data.
EUVD