CVE-2021-31849

Publication date

2021-11-01 19:25:13

Family

trellix

State

PUBLISHED

Description

SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.