Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
2020-07-15T15:15:11.503
2024-11-21T05:37:00.217
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | web_gateway | < 7.8.2.22 | Yes |
Application | mcafee | web_gateway | < 8.2.9 | Yes |
Application | mcafee | web_gateway | < 9.2.1 | Yes |