CVE-2017-3948

Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
intelCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
mcafeedata_loss_prevention_endpoint
10.0
mcafeedata_loss_prevention_endpoint
10.0.100
mcafeedata_loss_prevention_endpoint
10.0.200
mcafeedata_loss_prevention_endpoint
10.0.230
mcafeedata_loss_prevention_endpoint
10.0.250
𝑥
= Vulnerable software versions