DLP ePO extension - Cross-site scripting
CVE-2020-7303
4.1MEDIUM
Summary
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.
Affected Version(s)
DLP ePO extension 11.3 < 11.3.28
DLP ePO extension 11.4 < 11.4.200
DLP ePO extension 11.5 < 11.5.3
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved