McAfee ePO Cross-Site Scripting vulnerability
CVE-2021-31835

4.8MEDIUM

Key Information:

Vendor
Mcafee,llc
Status
Mcafee Epolicy Orchestrator (epo)
Vendor
CVE Published:
22 October 2021

Summary

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.

Affected Version(s)

McAfee ePolicy Orchestrator (ePO) < 5.10 CU 11

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.