### [CVE-2015-2760](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2760) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - https://kc.mcafee.com/corporate/index?page=content&id=SB10111 #### Github No PoCs found on GitHub currently.