SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability
CVE-2017-3961

3.5LOW

Key Information:

Vendor
Mcafee
Vendor
CVE Published:
25 May 2018

Summary

Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.

Affected Version(s)

Network Security Management (NSM) x86 8.2.7.42.2

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.