First published: Mon Nov 01 2021(Updated: )
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.
Credit: trellixpsirt@trellix.com psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention Endpoint | >=11.6.0<11.6.400 | |
Mcafee Data Loss Prevention Endpoint | >=11.7.0<11.7.100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31848 is a cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to version 11.7.100.
A remote attacker can exploit CVE-2021-31848 by convincing a logged in DLP ePO administrator to click on a carefully crafted link in the case management part of the system.
The severity of CVE-2021-31848 is rated as high with a CVSS score of 5.4.
CVE-2021-31848 affects McAfee Data Loss Prevention (DLP) ePO extension versions from 11.6.0 to 11.6.400, and versions from 11.7.0 to 11.7.100.
To fix CVE-2021-31848, it is recommended to update McAfee Data Loss Prevention (DLP) ePO extension to version 11.7.100 or later.