First published: Thu Jun 03 2021(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Database Security | <4.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-31830.
The severity of CVE-2021-31830 is medium with a severity value of 4.8.
McAfee Database Security (DBSec) prior to 4.8.2 is affected by CVE-2021-31830.
CVE-2021-31830 occurs due to improper neutralization of input during web page generation, allowing for cross-site scripting (XSS) attacks.
Yes, a fix is available for CVE-2021-31830. It is recommended to update to McAfee Database Security (DBSec) version 4.8.2 or later.