First published: Tue Feb 14 2012(Updated: )
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Server | =2010 | |
Microsoft SharePoint Server | =2010-sp1 | |
Microsoft SharePoint Foundation | =2010 | |
Microsoft SharePoint Foundation | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0145 has a severity level that is classified as high due to its potential impact on user data and security.
To fix CVE-2012-0145, it is recommended to apply the security updates provided by Microsoft for affected versions of SharePoint Server and SharePoint Foundation.
CVE-2012-0145 affects users of Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010, specifically those running the gold and SP1 versions.
CVE-2012-0145 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
The potential impact of CVE-2012-0145 includes the possibility of unauthorized actions being performed on behalf of users or exposure of sensitive information.