PT-2021-19535 · Mcafee · Mcafee Data Loss Prevention Endpoint
Published
2021-06-09
·
Updated
2023-11-16
·
CVE-2021-31832
CVSS v3.1
5.2
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Data Loss Prevention (DLP) Endpoint for Windows versions prior to 11.6.200
Description
The issue allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.
Recommendations
For versions prior to 11.6.200, update to version 11.6.200 or later to resolve the issue. As a temporary workaround, consider restricting access to the alert configuration text field to prevent JavaScript code injection until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Data Loss Prevention Endpoint