Medium severity4.8NVD Advisory· Published May 15, 2019· Updated Jun 17, 2026
CVE-2019-3602
CVE-2019-3602
Description
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.
Affected products
8cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*range: <9.1
- cpe:2.3:a:mcafee:network_security_manager:9.1:-:*:*:*:*:*:*
- cpe:2.3:a:mcafee:network_security_manager:9.1:update_1:*:*:*:*:*:*
- cpe:2.3:a:mcafee:network_security_manager:9.1:update_2:*:*:*:*:*:*
- cpe:2.3:a:mcafee:network_security_manager:9.1:update_3:*:*:*:*:*:*
- cpe:2.3:a:mcafee:network_security_manager:9.1:update_4:*:*:*:*:*:*
- Range: <9.1 Update 5
- McAfee, LLC/McAfee Network Security Manager (NSM)v5Range: 9.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.