Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: trellix

Published: 2021-12-09T15:55:17

Updated: 2021-12-09T15:55:17

Reserved: 2021-12-01T00:00:00


Link: CVE-2021-4038

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-09T16:15:08.610

Modified: 2023-11-16T03:06:23.680


Link: CVE-2021-4038

JSON object: View

cve-icon Redhat Information

No data.

CWE