Learn about CVE-2020-7317, a Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) allowing injection of arbitrary web script or HTML. Find mitigation steps and affected versions.
A Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows injection of arbitrary web script or HTML.
Understanding CVE-2020-7317
This CVE involves a Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) that can be exploited by administrators to inject malicious web script or HTML.
What is CVE-2020-7317?
CVE-2020-7317 is a security vulnerability in McAfee ePolicy Orchistrator (ePO) that enables the injection of arbitrary web script or HTML through unsanitized parameter values.
The Impact of CVE-2020-7317
The vulnerability has a CVSS base score of 4.6, indicating a medium severity issue with low confidentiality and integrity impacts. It requires user interaction for exploitation and has a low attack complexity.
Technical Details of CVE-2020-7317
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The vulnerability in McAfee ePolicy Orchistrator (ePO) allows administrators to inject arbitrary web script or HTML via unsanitized parameter values for 'syncPointList'.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by administrators injecting malicious web script or HTML through parameter values for 'syncPointList'.
Mitigation and Prevention
Protecting systems from CVE-2020-7317 involves immediate steps and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure that McAfee ePolicy Orchistrator (ePO) is updated to version 5.10.9 Update 9 to mitigate the vulnerability.