High severity8.4NVD Advisory· Published Nov 1, 2021· Updated Jun 17, 2026
CVE-2021-31849
CVE-2021-31849
Description
SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
Affected products
3- cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*Range: >=11.6.0,<11.6.400
<11.7.100+ 1 more
- (no CPE)range: <11.7.100
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- kc.mcafee.com/corporate/indexnvdBroken Link
News mentions
0No linked articles in our index yet.