Cross-Site Scripting Vulnerability in Symantec DLP Software
CVE-2019-9701
4.8MEDIUM
What is CVE-2019-9701?
The Symantec Data Loss Prevention (DLP) 15.5 MP1 and earlier versions are vulnerable to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious client-side scripts into web pages viewed by other users. Exploiting this weakness could enable attackers to bypass security measures such as the same-origin policy, leading to unauthorized actions on behalf of the user. It is crucial for organizations using affected versions to apply security patches and implement web application security best practices to mitigate potential risks.
Affected Version(s)
Data Loss Prevention Prior to and including DLP 15.5 MP1