Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2021-31834

Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

  • Published: Oct 22, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-31834
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
mcafee / epolicy_orchestrator 5.10.0-update_1 5.10.0-update_1.x
mcafee / epolicy_orchestrator 5.10.0-update_2 5.10.0-update_2.x
mcafee / epolicy_orchestrator 5.10.0-update_3 5.10.0-update_3.x
mcafee / epolicy_orchestrator 5.10.0 5.10.0.x
mcafee / epolicy_orchestrator 5.10.0-update_4 5.10.0-update_4.x
mcafee / epolicy_orchestrator 5.10.0-update_5 5.10.0-update_5.x
mcafee / epolicy_orchestrator 5.10.0-update_6 5.10.0-update_6.x
mcafee / epolicy_orchestrator - 5.10.0
mcafee / epolicy_orchestrator 5.10.0-update_7 5.10.0-update_7.x
mcafee / epolicy_orchestrator 5.10.0-update_8 5.10.0-update_8.x
mcafee / epolicy_orchestrator 5.10.0-update_9 5.10.0-update_9.x
mcafee / epolicy_orchestrator 5.10.0-update_10 5.10.0-update_10.x