CVE-2017-3933: McAfee Network Data Loss Prevention
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
Affected products
- McAfee Network Data Loss Prevention: version 9.3.0 only; version 9.3.1 only; version 9.3.2 only; version 9.3.3 only; version 9.3.4 only
Published 2017-10-31. Last modified 2026-06-17.