CVE-2017-3902

MEDIUM

Intel Security ePO <5.1.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.

Scores

CVSS v3 5.4
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (5)

mcafee/epolicy_orchestrator
mcafee/epolicy_orchestrator
mcafee/epolicy_orchestrator
mcafee/epolicy_orchestrator
Intel/ePO < 5.1.3, 5.1.2, 5.1.1, and 5.1.0

Timeline

Published Feb 13, 2017
Tracked Since Feb 18, 2026