PT-2013-4203 · Microsoft · Sharepoint Server+1

Benjamin Kunz Mejri

·

Published

2013-09-11

·

Updated

2018-10-12

·

CVE-2013-3179

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server versions 2007 SP3 through 2013
Description The issue allows remote attackers to inject arbitrary web script or HTML via a crafted request. An attacker who successfully exploits this could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Recommendations For Microsoft SharePoint Server versions 2007 SP3 through 2013, update to a version that includes the fix for this issue to prevent cross-site scripting attacks. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3179

Affected Products

Sharepoint Server
Sharepoint Foundation