cve/2020/CVE-2020-7309.md

19 lines
868 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-7309](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7309)
![](https://img.shields.io/static/v1?label=Product&message=McAfee%20Application%20and%20Change%20Control%20&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8.3.1%3C%208.3.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen)
### Description
Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10324
2024-06-09 00:33:16 +00:00
- https://kc.mcafee.com/corporate/index?page=content&id=SB10324
2024-05-25 21:48:12 +02:00
#### Github
No PoCs found on GitHub currently.