CVE-2021-31830
Cross site Scripting (XSS) vulnerability in McAfee DBSec
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.
Una vulnerabilidad de Neutralización Inapropiada de Entrada durante la Generación de Página Web ("Cross-site Scripting") en McAfee Database Security (DBSec) versiones anteriores a 4.8.2, permite a un administrador insertar código JavaScript cuando se configura el nombre de una base de datos para ser monitoreada. Esto podría ser desencadenado cuando cualquier usuario autorizado inicie sesión en la interfaz de DBSec y abra la página de configuración de propiedades de esta base de datos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-27 CVE Reserved
- 2021-06-03 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10359 | 2023-11-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Database Security Search vendor "Mcafee" for product "Database Security" | < 4.8.2 Search vendor "Mcafee" for product "Database Security" and version " < 4.8.2" | - |
Affected
|