First published: Wed Mar 13 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Foundation | =2010-sp1 | |
Microsoft SharePoint Server | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0083 is rated as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
To fix CVE-2013-0083, it is recommended to apply the latest security updates provided by Microsoft for SharePoint Server 2010 SP1.
The potential impacts of CVE-2013-0083 include unauthorized execution of administrative commands and manipulation of web content.
CVE-2013-0083 affects Microsoft SharePoint Foundation 2010 SP1 and Microsoft SharePoint Server 2010 SP1.
Mitigation for CVE-2013-0083 includes implementing web application firewall rules to help block potential cross-site scripting attempts.