TROYANOSYVIRUS
Back to CVEs

CVE-2021-31832

MEDIUM
5.2

Description

Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.

CVE Details

CVSS v3.1 Score5.2
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published6/9/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

mcafee:data_loss_prevention

Weaknesses (CWE)

CWE-79CWE-79

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.