Cross site scripting vulnerability in DLP Endpoint for Windows
Vulnerability Description
Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31832
Credits & Attribution
No credits recorded in the NVD database.
More from McAfee,LLC
View All →Affected Vendor
McAfee,LLC
View all reports →