CVE-2020-7317Cross-site Scripting in Epolicy Orchistrator

Severity
4.3MEDIUMNVD
CNA4.6
EPSS
0.1%
top 65.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 24

Description

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.2 | Impact: 2.7

Affected Packages2 packages

CVEListV5mcafee/epolicy_orchistratorunspecified5.10.9 update 9
NVDmcafee/epolicy_orchestrator5.10.05.10.9+1

🔴Vulnerability Details

2
GHSA
GHSA-4phr-gcpq-3v8p: Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 52022-05-24
CVEList
ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerability2020-10-14
CVE-2020-7317 — Cross-site Scripting in Mcafee | cvebase