CVE-2023-3946: XSS
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3946?
CVE-2023-3946 is a reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1 that allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session.
How does CVE-2023-3946 affect McAfee ePolicy Orchestrator?
CVE-2023-3946 affects McAfee ePolicy Orchestrator versions 5.10.0 through 5.10.0-update_15.
What is the severity of CVE-2023-3946?
CVE-2023-3946 has a severity rating of 6.1 (medium).
How can an attacker exploit CVE-2023-3946?
An attacker can exploit CVE-2023-3946 by convincing an authenticated ePO administrator to click on a carefully crafted link.
Where can I find more information about CVE-2023-3946?
You can find more information about CVE-2023-3946 at this link: [https://kcm.trellix.com/corporate/index?page=content&id=SB10402]