CVE-2021-31851 MEDIUM

CVE-2021-31851: Cross-Site Scripting vulnerability in Policy Auditor

Vendor Mcafee,Llc
Product McAfee Policy Auditor
Weakness CWE-79 · XSS
Published November 23, 2021
Last update August 3, 2024

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extraction of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.

Key dates

02Disclosure timeline

November 23, 2021 CVE published
August 3, 2024 Record updated