First published: Wed Oct 14 2020(Updated: )
Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | <=5.9.1 | |
Trellix ePolicy Orchestrator | >=5.10.0<=5.10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7317 is categorized as a cross-site scripting vulnerability which may allow attackers to inject arbitrary web scripts or HTML.
To fix CVE-2020-7317, upgrade to McAfee ePolicy Orchestrator version 5.10.9 Update 9 or later.
CVE-2020-7317 affects McAfee ePolicy Orchestrator versions prior to 5.10.9 Update 9, specifically versions up to 5.9.1 and between 5.10.0 and 5.10.9.
Yes, CVE-2020-7317 can be exploited remotely if an administrator accesses a crafted URL containing the vulnerable parameter.
The impact of CVE-2020-7317 includes potential unauthorized execution of scripts in the context of the user's browser, leading to data theft or session hijacking.