kc.mcafee.com
https://kc.mcafee.com/corporate/index?page=content&id=SB10326 CVE-2020-7302
MEDIUM
DLP ePO extension - Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-7302 has a selected CVSS score of 5.4 (medium).
Description
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DLP ePO extensionBrowse McAfee / DLP ePO extension | CVE List | 11.3 to < 11.3.28 | affected |
| 11.4 to < 11.4.200 | affected | ||
| 11.5 to < 11.5.3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-7302