CVE-2014-9230
Symantec Data Loss Prevention < 12.5.2 - Cross-Site Scripting in Administration Console
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75288
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032710
Vendor Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150622_00
Scores
EPSS
0.0061
EPSS Percentile
70.0%
Details
CWE
CWE-79
Status
published
Products (1)
symantec/data_loss_prevention
< 12.5.1
Published
Jun 28, 2015
Tracked Since
Feb 18, 2026