CVE-2020-7302: DLP ePO extension - Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7302?
CVE-2020-7302 is a vulnerability that allows authenticated attackers to upload malicious files to the McAfee Data Loss Prevention (DLP) ePO extension prior to version 11.5.3.
How severe is CVE-2020-7302?
CVE-2020-7302 has a severity rating of 6.4 (Medium).
Which versions of McAfee Data Loss Prevention (DLP) are affected by CVE-2020-7302?
CVE-2020-7302 affects McAfee Data Loss Prevention (DLP) versions 11.3.0 to 11.3.28, 11.4.0 to 11.4.200, and 11.5.0 to 11.5.3.
How can an authenticated attacker exploit CVE-2020-7302?
An authenticated attacker can exploit CVE-2020-7302 by uploading malicious files to the DLP case management section via lack of sanity checking.
Is there a fix available for CVE-2020-7302?
Yes, McAfee has released a fix for CVE-2020-7302. It is recommended to update to version 11.5.3 or later of McAfee Data Loss Prevention (DLP) ePO extension.