CVE-2019-3602

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/05/2019
Last modified:
07/11/2023

Description

Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:* 9.1 (excluding)
cpe:2.3:a:mcafee:network_security_manager:9.1:-:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_1:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_2:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_3:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_4:*:*:*:*:*:*