Loading HuntDB...

GHSA-xr2m-8rhq-x323

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

Related CVEs

Key Information

GHSA ID
GHSA-xr2m-8rhq-x323
Published
May 24, 2022 7:03 PM
Last Modified
November 16, 2023 3:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.