First published: Mon Apr 02 2018(Updated: )
Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | =5.3.0 | |
Trellix ePolicy Orchestrator | =5.3.1 | |
Trellix ePolicy Orchestrator | =5.3.2 | |
Trellix ePolicy Orchestrator | =5.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6659 is classified as a medium-severity reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2018-6659, update McAfee ePolicy Orchestrator to a version that is not affected by this vulnerability.
CVE-2018-6659 affects McAfee ePolicy Orchestrator versions 5.3.0, 5.3.1, 5.3.2, and 5.9.0.
CVE-2018-6659 is a reflected cross-site scripting (XSS) vulnerability.
CVE-2018-6659 can be exploited by remote authenticated users.