Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc2g-2g3x-j4c9

Опубликовано: 24 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

EPSS

Процентиль: 37%
0.00155
Низкий

3.8 Low

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

EPSS

Процентиль: 37%
0.00155
Низкий

3.8 Low

CVSS3

Дефекты

CWE-611