Vulnerability Description
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Data Loss Prevention Endpoint | <= 9.3.400 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/73193
- https://kc.mcafee.com/corporate/index?page=content&id=SB10111Vendor Advisory
- http://www.securityfocus.com/bid/73193
- https://kc.mcafee.com/corporate/index?page=content&id=SB10111Vendor Advisory
FAQ
What is CVE-2015-2760?
CVE-2015-2760 is a vulnerability with a CVSS score of 3.5 (LOW). Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitr...
How severe is CVE-2015-2760?
CVE-2015-2760 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2760?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Data Loss Prevention Endpoint.