First published: Thu Sep 15 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Sharepoint Services | =3.0-sp2 | |
Microsoft Sharepoint Services | =3.0-sp2 | |
Microsoft SharePoint Foundation | =2010 | |
Microsoft SharePoint Foundation | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1891 is considered a moderate severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2011-1891, install the security updates provided by Microsoft for SharePoint Services and SharePoint Foundation.
CVE-2011-1891 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data and application integrity.
CVE-2011-1891 affects Microsoft SharePoint Services 3.0 SP2 and Microsoft SharePoint Foundation 2010, including SP1.
The attack vector for CVE-2011-1891 involves sending crafted requests that contain malicious scripts to vulnerable SharePoint systems.