PT-2021-4989 · Mcafee · Mcafee Policy Auditor

CVE-2021-31852

·

Published

2021-11-22

·

Updated

2023-11-21

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions McAfee Policy Auditor versions prior to 6.5.2
Description The issue is related to a Reflected Cross-Site Scripting vulnerability in the web interface of McAfee Policy Auditor. This vulnerability allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface, which could lead to the extraction of end-user session tokens or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.
Recommendations For McAfee Policy Auditor versions prior to 6.5.2, update to version 6.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable web interface until a patch is applied. Avoid using the UID parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05752
CVE-2021-31852

Affected Products

Mcafee Policy Auditor