CVE-2019-3638

Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:10

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10294 - Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10294 -

13 Dec 2022, 17:28

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : 6.1
v2 : 4.3
v3 : 9.6

Information

Published : 2019-09-12 16:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-3638

Mitre link : CVE-2019-3638

CVE.ORG link : CVE-2019-3638


JSON object : View

Products Affected

mcafee

  • web_gateway
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')