CVE-2017-3967Code Injection in Network Security Management

CWE-94Code Injection2 documents2 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 58.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 13

Description

Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5mcafee/network_security_management8.28.2.7.42.2

🔴Vulnerability Details

1
GHSA
GHSA-v66p-hmjm-wrxm: Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 82022-05-13