Description
Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Attack Vector
- network
- Complexity
- low
- Privileges
- low
- User Action
- required
- Scope
- changed
- Confidentiality
- low
- Integrity
- low
- Availability
- none
- Weaknesses
- CWE-79CWE-79
Metadata
- Primary Vendor
- MCAFEE
- Published
- 10/22/2021
- Last Modified
- 11/21/2024
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
mcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestrator
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.