CVE-2021-23881: Stored Cross Site Scripting in ENS
A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-23881.
What is the severity of CVE-2021-23881?
The severity of CVE-2021-23881 is medium with a severity value of 4.8.
Which software is affected by CVE-2021-23881?
The affected software is McAfee Endpoint Security (ENS) prior to version 10.7.0.
How can an ENS ePO administrator exploit CVE-2021-23881?
An ENS ePO administrator can add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user accesses the policy event.
Is there a fix available for CVE-2021-23881?
Yes, a fix is available in McAfee Endpoint Security (ENS) version 10.7.0 February 2021 Update.