First published: Tue Dec 03 2019(Updated: )
API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee WebAdvisor | <4.1.1.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-3666 is medium with a severity value of 6.5.
An unauthenticated attacker can exploit CVE-2019-3666 by crafting a carefully crafted web site that allows the browser to navigate to restricted websites via the McAfee Web Advisor web interface.
McAfee Web Advisor prior to version 4.1.1.48 is affected by CVE-2019-3666.
No, CVE-2019-3666 can be exploited by an unauthenticated attacker.
You can find more information about CVE-2019-3666 at the following link: http://service.mcafee.com/FAQDocument.aspx?&id=TS102991