Back

CVE-2018-6229

CRITICAL

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

Published: Mar 15, 2018 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
trendmicro email_encryption_gateway 5.5

GitHub Security Advisory GHSA-mpmp-5r2x-4jvg

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 10.44%

Top 5% most likely to be exploited

Threat Score 42.3 / 100

Data Sources

NVD EPSS GitHub