Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-10814 | Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-03T19:14:09.497Z
Reserved: 2021-01-12T00:00:00
Link: CVE-2021-23888
No data.
Status : Modified
Published: 2021-03-26T10:15:11.833
Modified: 2024-11-21T05:52:00.557
Link: CVE-2021-23888
No data.
OpenCVE Enrichment
No data.
EUVD