XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.
Fixes

Solution

The FireEye team is working on fixing the reported vulnerabilities. It is recommended to update affected products to the latest version available.


Workaround

No workaround given by the vendor.

History

Tue, 03 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-03T14:00:17.084Z

Reserved: 2024-01-08T11:55:59.441Z

Link: CVE-2024-0314

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:48.586Z

cve-icon NVD

Status : Modified

Published: 2024-01-15T16:15:12.793

Modified: 2024-11-21T08:46:18.317

Link: CVE-2024-0314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.