Описание
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.
Уязвимые конфигурации
Конфигурация 1Версия до 9.1 (исключая)
Одно из
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:-:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_1:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_2:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_3:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_4:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00265
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
больше 3 лет назад
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.
EPSS
Процентиль: 50%
0.00265
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79