Record summary

CVE-2019-9701 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Data Loss Prevention

CVE ListPrior to and including DLP 15.5 MP1affected

Proofs of concept

1

Catalogued exploits

ExploitDBSymantec DLP 15.5 MP1 - Cross-Site ScriptingExploitDB exploitby Chapman SchleissNot analyzed1 file
ExploitDB

PoC details

References

3