Vulnerabilities > CVE-2024-0320 - Unspecified vulnerability in Fireeye Malware Analysis 9.0.3.936530

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
fireeye

Summary

Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application URL to retrieve the session details of a legitimate user.

Vulnerable Configurations

Part Description Count
Application
Fireeye
1