CVE-2019-3602

Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:-:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_1:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_2:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_3:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:9.1:update_4:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/108400 - () http://www.securityfocus.com/bid/108400 -
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10281 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10281 -

07 Nov 2023, 03:09

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10281 - Patch, Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10281 -
References (BID) http://www.securityfocus.com/bid/108400 - () http://www.securityfocus.com/bid/108400 -

Information

Published : 2019-05-15 16:29

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3602

Mitre link : CVE-2019-3602

CVE.ORG link : CVE-2019-3602


JSON object : View

Products Affected

mcafee

  • network_security_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')