{"api_version":"1","generated_at":"2026-07-23T10:04:42+00:00","cve":"CVE-2020-7302","urls":{"html":"https://cve.report/CVE-2020-7302","api":"https://cve.report/api/cve/CVE-2020-7302.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7302","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7302"},"summary":{"title":"CVE-2020-7302","description":"Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.","state":"PUBLIC","assigner":"psirt@mcafee.com","published_at":"2020-08-13 03:15:00","updated_at":"2023-11-07 03:25:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","refsource":"","tags":[],"title":"McAfee Security Bulletin - Data Loss Prevention for Mac agent and Data Loss Prevention ePO extension address eight vulnerabilities (CVE-2020-7300, CVE-2020-7301, CVE-2020-7302, CVE-2020-7303, CVE-2020-7304, CVE-2020-7305, CVE-2020-7306, and CVE-2020-7307)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7302","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7302","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"7302","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7302","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@mcafee.com","ID":"CVE-2020-7302","STATE":"PUBLIC","TITLE":"DLP ePO extension - Unrestricted Upload of File with Dangerous Type"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"DLP ePO extension","version":{"version_data":[{"version_affected":"<","version_name":"11.3","version_value":"11.3.28"},{"version_affected":"<","version_name":"11.4","version_value":"11.4.200"},{"version_affected":"<","version_name":"11.5","version_value":"11.5.3"}]}}]},"vendor_name":"McAfee"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-434 Unrestricted Upload of File with Dangerous Type"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326"}]},"source":{"advisory":"SB10326","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-08-13 03:15:00","lastModifiedDate":"2023-11-07 03:25:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.1,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.28","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.200","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7302","Ordinal":"167581","Title":"CVE-2020-7302","CVE":"CVE-2020-7302","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7302","Ordinal":"1","NoteData":"Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7302","Ordinal":"2","NoteData":"2020-08-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7302","Ordinal":"3","NoteData":"2020-08-12","Type":"Other","Title":"Modified"}]}}}