Vulnerability Details CVE-2021-31848
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.7%
CVSS Severity
CVSS v3 Score 8.4
CVSS v2 Score 3.5
Products affected by CVE-2021-31848
-
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*
-
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:11.6.0
-
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:11.6.100.41