CVE-2017-3948
CVE-2017-3948
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Jun 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
Affected products
McAfee · Data Loss Prevention Endpoint (DLPe)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →