Cross-Site Scripting Vulnerability in McAfee Network Data Loss Prevention
CVE-2017-4011

6.1MEDIUM

Key Information:

Vendor
Mcafee
Vendor
CVE Published:
17 May 2017

Summary

A Cross-Site Scripting (XSS) vulnerability exists in McAfee Network Data Loss Prevention (NDLP) 9.3.x, which allows remote attackers to inject malicious scripts through HTTP headers. This can lead to unauthorized access to session and cookie information, potentially compromising user data and privacy. It emphasizes the necessity for proper input validation and security measures when handling HTTP requests.

Affected Version(s)

Network Data Loss Prevention (NDLP) 9.3.x

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.