CVE-2013-4883: XSS
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do; uid parameter to (4) ComputerMgmt/sysDetPanelBoolPie.do or (5) ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7) orion.user.security.token, or (8) ajaxMode parameter to ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10) orion.user.security.token, or (11) ajaxMode parameter to ComputerMgmt/sysDetPanelSummary.do.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4883?
CVE-2013-4883 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2013-4883?
To fix CVE-2013-4883, upgrade the McAfee ePolicy Orchestrator to version 4.6.7 or later.
What are the potential impacts of exploiting CVE-2013-4883?
Exploiting CVE-2013-4883 could allow attackers to execute arbitrary script code in the context of the user's browser.
Which versions of McAfee ePolicy Orchestrator are affected by CVE-2013-4883?
CVE-2013-4883 affects McAfee ePolicy Orchestrator 4.6.6 and earlier versions.
Is McAfee Agent impacted by CVE-2013-4883?
Yes, the ePO Extension for the McAfee Agent versions 4.5 through 4.6 are affected by CVE-2013-4883.