ZeroHour

CVE-2021-23888

CVSS 3.1
6.3 medium
EPSS
<1%p47
Published
()
Modified
Description

Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.

Vendors
mcafee
Products
epolicy orchestrator
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.