First published: Wed Oct 14 2020(Updated: )
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | >=5.10.0<=5.10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7318 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
To fix CVE-2020-7318, upgrade McAfee ePolicy Orchestrator to version 5.10.9 Update 9 or later.
CVE-2020-7318 affects McAfee ePolicy Orchestrator versions prior to 5.10.9 Update 9.
CVE-2020-7318 is a Cross-Site Scripting vulnerability allowing for the injection of arbitrary web scripts or HTML.
Administrators of McAfee ePolicy Orchestrator versions prior to 5.10.9 Update 9 are impacted by CVE-2020-7318.