Cross-Site Scripting Vulnerability in McAfee Network Data Loss Prevention
CVE-2017-4011
6.1MEDIUM
Key Information:
- Vendor
- Mcafee
- Vendor
- CVE Published:
- 17 May 2017
Summary
A Cross-Site Scripting (XSS) vulnerability exists in McAfee Network Data Loss Prevention (NDLP) 9.3.x, which allows remote attackers to inject malicious scripts through HTTP headers. This can lead to unauthorized access to session and cookie information, potentially compromising user data and privacy. It emphasizes the necessity for proper input validation and security measures when handling HTTP requests.
Affected Version(s)
Network Data Loss Prevention (NDLP) 9.3.x
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved