Arbitrary Code Injection Vulnerability in McAfee Application Control (MAC) ePO Extension

Arbitrary Code Injection Vulnerability in McAfee Application Control (MAC) ePO Extension

CVE-2020-7309 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.

Learn more about our Web App Pen Testing.