PT-2015-2787 · Microsoft · Exchange Server 2013+1

Published

2015-06-09

·

Updated

2018-10-12

·

CVE-2015-2359

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2013 Cumulative Update 8
Description The issue is related to a cross-site scripting (XSS) vulnerability, also referred to as an "Exchange HTML Injection Vulnerability", which allows remote attackers to inject arbitrary web script or HTML. This is due to the lack of protection measures for the web page structure, enabling an attacker to exploit the vulnerability and inject malicious code. The vulnerability exists because Microsoft Exchange does not properly sanitize HTML strings, allowing an attacker to submit a specially crafted script to a target site. This script could then be run in the security context of a user who views the malicious content.
Recommendations For Microsoft Exchange Server 2013 Cumulative Update 8, consider disabling the web applications until a patch is available to prevent exploitation of the HTML Injection vulnerability. Restrict access to the web applications to minimize the risk of exploitation. Avoid using the affected web applications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12152
CVE-2015-2359

Affected Products

Exchange Server
Exchange Server 2013