CVE-2017-3948: XSS
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3948?
CVE-2017-3948 is considered a medium severity vulnerability due to its potential for Cross Site Scripting attacks.
How do I fix CVE-2017-3948?
To fix CVE-2017-3948, update the McAfee Data Loss Prevention Endpoint to a version that has patched the XSS vulnerability.
Who is affected by CVE-2017-3948?
Authenticated users of McAfee Data Loss Prevention Endpoint versions 10.0.x are affected by CVE-2017-3948.
What type of attack does CVE-2017-3948 enable?
CVE-2017-3948 enables Cross Site Scripting (XSS) attacks through injection of malicious JavaScript into a user's session.
Is there a workaround for CVE-2017-3948?
Currently, the best mitigation for CVE-2017-3948 is to apply the available security updates from McAfee.