First published: Thu Sep 15 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Sharepoint Services | =3.0-sp2 | |
Microsoft Sharepoint Services | =3.0-sp2 | |
Microsoft Sharepoint Services | =2.0 | |
Microsoft SharePoint Foundation | =2010 | |
Microsoft SharePoint Server | =2010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1893 has a critical severity rating due to its potential for cross-site scripting exploitation.
To fix CVE-2011-1893, apply the security updates provided by Microsoft for affected SharePoint products.
CVE-2011-1893 affects Microsoft Office SharePoint Server 2010, SharePoint Foundation 2010, and specific versions of Windows SharePoint Services.
CVE-2011-1893 allows attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized actions on behalf of users.
While no official workaround exists for CVE-2011-1893, minimizing exposure and restricting access to vulnerable SharePoint servers can help mitigate risks.