PT-2015-2013 · Microsoft · Sharepoint Foundation 2013 Sp1+1

Published

2015-09-08

·

Updated

2018-10-12

·

CVE-2015-2522

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Foundation 2013 SP1
Description The issue is related to a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web script or HTML via crafted content. This could enable an attacker to perform persistent cross-site scripting attacks, run script in the security context of the logged-on user, and potentially steal sensitive information, including authentication cookies and recently submitted data. The vulnerability exists due to the failure to properly sanitize user-supplied web requests.
Recommendations For Microsoft SharePoint Foundation 2013 SP1, consider restricting access to user-supplied web requests until a patch is available. As a temporary workaround, avoid submitting specially crafted content to target sites to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11359
CVE-2015-2522

Affected Products

Sharepoint Foundation 2013 Sp1
Sharepoint Foundation