First published: Fri Jun 23 2017(Updated: )
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Data Loss Prevention Endpoint | =10.0 | |
McAfee Data Loss Prevention Endpoint | =10.0.100 | |
McAfee Data Loss Prevention Endpoint | =10.0.200 | |
McAfee Data Loss Prevention Endpoint | =10.0.230 | |
McAfee Data Loss Prevention Endpoint | =10.0.250 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3948 is considered a medium severity vulnerability due to its potential for Cross Site Scripting attacks.
To fix CVE-2017-3948, update the McAfee Data Loss Prevention Endpoint to a version that has patched the XSS vulnerability.
Authenticated users of McAfee Data Loss Prevention Endpoint versions 10.0.x are affected by CVE-2017-3948.
CVE-2017-3948 enables Cross Site Scripting (XSS) attacks through injection of malicious JavaScript into a user's session.
Currently, the best mitigation for CVE-2017-3948 is to apply the available security updates from McAfee.