First published: Tue Dec 03 2019(Updated: )
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee WebAdvisor | <4.1.1.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-3665 is medium with a severity value of 6.5.
CVE-2019-3665 affects McAfee Web Advisor prior to version 4.1.1.48 by allowing remote unauthenticated attackers to bypass website blocking.
To fix the Code Injection vulnerability in McAfee Web Advisor CVE-2019-3665, upgrade to version 4.1.1.48 or later.
The Common Weakness Enumeration (CWE) ID for CVE-2019-3665 is 94.
You can find more information about CVE-2019-3665 in McAfee's FAQ document: http://service.mcafee.com/FAQDocument.aspx?&id=TS102991