Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.
References
Link | Resource |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10360 | Patch Vendor Advisory |
Configurations
Information
Published : 2021-06-09 07:15
Updated : 2021-06-22 09:33
NVD link : CVE-2021-31832
Mitre link : CVE-2021-31832
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
mcafee
- data_loss_prevention