NSM vulnerable to XSS
CVE-2021-4038
4.8MEDIUM
What is CVE-2021-4038?
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
Affected Version(s)
McAfee Network Security Manager (NSM) < 10.7 M7