CVE-2020-7303: DLP ePO extension - Cross-site scripting
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7303?
CVE-2020-7303 is a cross-site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to version 11.5.3.
How does CVE-2020-7303 affect users?
CVE-2020-7303 allows an authenticated remote user to trigger scripts to run in a user's browser via adding a new label.
What is the severity of CVE-2020-7303?
CVE-2020-7303 has a severity rating of 4.1 (medium).
Which versions of McAfee Data Loss Prevention are affected by CVE-2020-7303?
McAfee Data Loss Prevention versions 11.3.0 to 11.3.28, 11.4.0 to 11.4.200, and 11.5.0 to 11.5.3 are affected by CVE-2020-7303.
How can I fix CVE-2020-7303?
To fix CVE-2020-7303, users should upgrade to McAfee Data Loss Prevention version 11.5.3 or apply the necessary patches provided by McAfee.