A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: trellix
Published: 2021-02-10T10:30:15.368578Z
Updated: 2024-09-17T01:41:33.007Z
Reserved: 2021-01-12T00:00:00
Link: CVE-2021-23881
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-10T11:15:13.177
Modified: 2024-11-21T05:51:59.720
Link: CVE-2021-23881
Redhat
No data.