CVE-2017-4015UI Misrepresentation / Clickjacking in Network Data Loss Prevention

Severity
4.5MEDIUMNVD
EPSS
0.2%
top 54.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 17

Description

Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-qhmp-pxvc-gh7c: Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 92022-05-17

📐Framework References

1
CWE
Improper Restriction of Rendered UI Layers or Frames