CVE-2019-3666: API Abuse Vulnerability
API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3666?
The severity of CVE-2019-3666 is medium with a severity value of 6.5.
How can an unauthenticated attacker exploit CVE-2019-3666?
An unauthenticated attacker can exploit CVE-2019-3666 by crafting a carefully crafted web site that allows the browser to navigate to restricted websites via the McAfee Web Advisor web interface.
Which version of McAfee Web Advisor is affected by CVE-2019-3666?
McAfee Web Advisor prior to version 4.1.1.48 is affected by CVE-2019-3666.
Is authentication required for exploiting CVE-2019-3666?
No, CVE-2019-3666 can be exploited by an unauthenticated attacker.
Where can I find more information about CVE-2019-3666?
You can find more information about CVE-2019-3666 at the following link: http://service.mcafee.com/FAQDocument.aspx?&id=TS102991