Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.
2020-08-13T03:15:14.757
2024-11-21T05:37:01.670
Modified
CVSSv3.1: 7.6 (HIGH)
AV:A/AC:L/Au:S/C:P/I:P/A:P
5.1
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | data_loss_prevention | < 11.3.28 | Yes |
Application | mcafee | data_loss_prevention | < 11.4.200 | Yes |
Application | mcafee | data_loss_prevention | < 11.5.3 | Yes |