First published: Wed Sep 11 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Foundation | =2010-sp1 | |
Microsoft SharePoint Foundation | =2010-sp2 | |
Microsoft SharePoint Server | =2007-sp3 | |
Microsoft SharePoint Server | =2010-sp1 | |
Microsoft SharePoint Server | =2010-sp2 | |
Microsoft Sharepoint Services | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3179 is classified as a moderate severity vulnerability due to potential for XSS attacks.
To fix CVE-2013-3179, you should update to the latest security patches provided by Microsoft for affected SharePoint versions.
CVE-2013-3179 affects Microsoft SharePoint Server 2007 SP3, 2010 SP1, 2010 SP2, and SharePoint Foundation 2010 SP1 and SP2.
CVE-2013-3179 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
User input is not safe with CVE-2013-3179, as the vulnerability can be exploited through crafted requests.