Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.
2021-10-22T11:15:07.900
2024-11-21T06:06:19.430
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mcafee | epolicy_orchestrator | < 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
| Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |