CVE-2019-9701
MEDIUMSymantec Data Loss Prevention 15.5 MP1 and prior - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-9701. PoCs published by Chapman Schleiss.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Symantec DLP <= 15.5 MP1 via the 'name' parameter in a POST request. The payload executes JavaScript when a user hovers over the injected content, potentially stealing cookies or session data.
Description
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Symantec DLP <= 15.5 MP1 via the 'name' parameter in a POST request. The payload executes JavaScript when a user hovers over the injected content, potentially stealing cookies or session data.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N