CVE-2017-4015 — UI Misrepresentation / Clickjacking in Network Data Loss Prevention
CWE-1021 — UI Misrepresentation / ClickjackingCWE-20 — Improper Input Validation3 documents3 sources
Severity
4.5MEDIUMNVD
EPSS
0.2%
top 54.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 17
Description
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6