PT-2015-2787 · Microsoft · Exchange Server 2013+1
Published
2015-06-09
·
Updated
2018-10-12
·
CVE-2015-2359
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server 2013 Cumulative Update 8
Description
The issue is related to a cross-site scripting (XSS) vulnerability, also referred to as an "Exchange HTML Injection Vulnerability", which allows remote attackers to inject arbitrary web script or HTML. This is due to the lack of protection measures for the web page structure, enabling an attacker to exploit the vulnerability and inject malicious code. The vulnerability exists because Microsoft Exchange does not properly sanitize HTML strings, allowing an attacker to submit a specially crafted script to a target site. This script could then be run in the security context of a user who views the malicious content.
Recommendations
For Microsoft Exchange Server 2013 Cumulative Update 8, consider disabling the web applications until a patch is available to prevent exploitation of the HTML Injection vulnerability. Restrict access to the web applications to minimize the risk of exploitation. Avoid using the affected web applications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server
Exchange Server 2013