CVE-2017-3948 is a Cross-Site Scripting (XSS) vulnerability affecting McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x. Authenticated users can inject malicious JavaScript into a user's browsing session through IMG tags within the ePO extension. This vulnerability has a CVSS score of 5.4 (Medium), indicating a low-complexity attack requiring user interaction, with potential for limited confidentiality and integrity impact. The EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, nor is any public exploit code available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are also absent, indicating a lack of widespread attention or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:a:mcafee:data_loss_prevention_endpoint:10.0:*:*:*:*:*:*:* | ||
10.0.100CPE matchmatch criteria | cpe:2.3:a:mcafee:data_loss_prevention_endpoint:10.0.100:*:*:*:*:*:*:* | ||
10.0.200CPE matchmatch criteria | cpe:2.3:a:mcafee:data_loss_prevention_endpoint:10.0.200:*:*:*:*:*:*:* | ||
10.0.230CPE matchmatch criteria | cpe:2.3:a:mcafee:data_loss_prevention_endpoint:10.0.230:*:*:*:*:*:*:* | ||
10.0.250CPE matchmatch criteria | cpe:2.3:a:mcafee:data_loss_prevention_endpoint:10.0.250:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.