First published: Wed Apr 04 2018(Updated: )
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Security Manager | <8.2.7.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-3967.
The title of this vulnerability is 'Target influence via framing vulnerability in the web interface in McAfee Network Security Management'.
The affected software in this vulnerability is McAfee Network Security Manager before version 8.2.7.42.2.
The severity level of this vulnerability is medium with a CVSS score of 6.1.
To fix this vulnerability, update McAfee Network Security Manager to version 8.2.7.42.2 or later.