PT-2021-4989 · Mcafee · Mcafee Policy Auditor
Published
2021-11-22
·
Updated
2023-11-21
·
CVE-2021-31852
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Policy Auditor versions prior to 6.5.2
Description
The issue is related to a Reflected Cross-Site Scripting vulnerability in the web interface of McAfee Policy Auditor. This vulnerability allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the
UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface, which could lead to the extraction of end-user session tokens or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.Recommendations
For McAfee Policy Auditor versions prior to 6.5.2, update to version 6.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable web interface until a patch is applied. Avoid using the
UID parameter in the affected API endpoint until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Policy Auditor