Cross-Site Scripting in McAfee Email Gateway
CVE-2016-3969
6.1MEDIUM
Summary
The vulnerability in McAfee Email Gateway (MEG) 7.6.x versions prior to 7.6.404 is a cross-site scripting (XSS) issue that occurs when File Filtering is enabled with the action set to ESERVICES:REPLACE. This flaw allows remote attackers to exploit the system by injecting arbitrary web scripts or HTML through attachments in blocked emails. Addressing this vulnerability is crucial for maintaining the integrity and security of the email environment.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved