CVE-2021-31848: Data Loss Prevention (DLP) ePO extension - Cross site scripting (XSS)
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31848?
CVE-2021-31848 is a cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to version 11.7.100.
How can a remote attacker exploit CVE-2021-31848?
A remote attacker can exploit CVE-2021-31848 by convincing a logged in DLP ePO administrator to click on a carefully crafted link in the case management part of the system.
What is the severity of CVE-2021-31848?
The severity of CVE-2021-31848 is rated as high with a CVSS score of 5.4.
Which versions of McAfee Data Loss Prevention (DLP) ePO extension are affected by CVE-2021-31848?
CVE-2021-31848 affects McAfee Data Loss Prevention (DLP) ePO extension versions from 11.6.0 to 11.6.400, and versions from 11.7.0 to 11.7.100.
How do I fix CVE-2021-31848?
To fix CVE-2021-31848, it is recommended to update McAfee Data Loss Prevention (DLP) ePO extension to version 11.7.100 or later.