Record summary

CVE-2020-7318 has a selected CVSS score of 4.6 (medium); EIP currently links 1 Nuclei template.

Description

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 5.10.9 update 9affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMcAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site ScriptingCVSS 4.3

McAfee ePolicy Orchestrator before 5.10.9 Update 9 is vulnerable to a cross-site scripting vulnerability that allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized. reference: - https://swarm.ptsecurity.com/vulnerabilities-in-mcafee-epolicy-orchestrator/ - https://kc.mcafee.com/corporate/index?page=content&id=SB10332 - https://nvd.nist.gov/vuln/detail/CVE-2020-7318

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking or unauthorized actions.

Remediation

Upgrade to McAfee ePolicy Orchestrator version 5.10.9 Update 9 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdwisiswant0
Template tagscvecve2020xssmcafeevuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2