Cross-Site Scripting Vulnerabilities in Symantec Endpoint Protection Manager
CVE-2016-3652
5.4MEDIUM
What is CVE-2016-3652?
Multiple cross-site scripting (XSS) vulnerabilities exist in management scripts of Symantec Endpoint Protection Manager (SEPM) 12.1 prior to RU6 MP5. These vulnerabilities enable remote authenticated users to inject arbitrary web scripts or HTML through unspecified vectors, potentially compromising the integrity of web sessions and sensitive data.