{"api_version":"1","generated_at":"2026-07-23T09:03:15+00:00","cve":"CVE-2020-7301","urls":{"html":"https://cve.report/CVE-2020-7301","api":"https://cve.report/api/cve/CVE-2020-7301.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7301","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7301"},"summary":{"title":"CVE-2020-7301","description":"Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section.","state":"PUBLIC","assigner":"psirt@mcafee.com","published_at":"2020-08-12 22:15:00","updated_at":"2023-11-07 03:25:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","refsource":"","tags":[],"title":"McAfee Security Bulletin - Data Loss Prevention for Mac agent and Data Loss Prevention ePO extension address eight vulnerabilities (CVE-2020-7300, CVE-2020-7301, CVE-2020-7302, CVE-2020-7303, CVE-2020-7304, CVE-2020-7305, CVE-2020-7306, and CVE-2020-7307)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7301","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7301","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"7301","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7301","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@mcafee.com","ID":"CVE-2020-7301","STATE":"PUBLIC","TITLE":"DLP ePO extension - Cross site scripting"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"DLP ePO extension","version":{"version_data":[{"version_affected":"<","version_name":"11.3","version_value":"11.3.28"},{"version_affected":"<","version_name":"11.4","version_value":"11.4.200"},{"version_affected":"<","version_name":"11.5","version_value":"11.5.3"}]}}]},"vendor_name":"McAfee"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":4.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326"}]},"source":{"advisory":"SB10326","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-08-12 22:15:00","lastModifiedDate":"2023-11-07 03:25:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.6,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.1,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.28","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.200","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7301","Ordinal":"167580","Title":"CVE-2020-7301","CVE":"CVE-2020-7301","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7301","Ordinal":"1","NoteData":"Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7301","Ordinal":"2","NoteData":"2020-08-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7301","Ordinal":"3","NoteData":"2020-08-12","Type":"Other","Title":"Modified"}]}}}