Loading HuntDB...

GHSA-qpvw-vv3x-9vf4

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.

Related CVEs

Key Information

GHSA ID
GHSA-qpvw-vv3x-9vf4
Published
March 24, 2022 12:00 AM
Last Modified
March 30, 2022 12:01 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.