Back to Database
Status published
Medium
CVE-2021-31835
McAfee ePO Cross-Site Scripting vulnerability
Vulnerability Description
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31835
Credits & Attribution
No credits recorded in the NVD database.
More from McAfee,LLC
View All →CVE-2022-1824
McAfee MCPR privilege escalation
High
7.9
CVE-2022-1823
McAfee MCPR privilege escalation
High
7.9
CVE-2022-1258
SQL injection vulnerability in McAfee Agent's ePO extension
High
8.4
CVE-2022-1257
Improper Verification of Cryptographic Signature by McAfee Agent
Medium
6.1
CVE-2022-1256
Improper Privilege Management in McAfee Agent for Windows
High
7.8
Affected Vendor
McAfee,LLC
View all reports →Affected Software
McAfee ePolicy Orchestrator (ePO)
Vulnerable Versions:
unspecified
Timeline
Official Publish:
October 22nd, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N