Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published: 2021-12-09T15:55:17

Updated: 2024-08-03T17:16:03.446Z

Reserved: 2021-12-01T00:00:00

Link: CVE-2021-4038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-09T16:15:08.610

Modified: 2023-11-16T03:06:23.680

Link: CVE-2021-4038

cve-icon Redhat

No data.