First published: Wed Sep 11 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Foundation 2013 | =2010-sp1 | |
Microsoft SharePoint Foundation 2013 | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2010-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3180 is considered a critical severity vulnerability due to its potential for allowing remote attacks via XSS.
To fix CVE-2013-3180, apply the security update provided in the Microsoft security bulletin MS13-067.
CVE-2013-3180 affects Microsoft SharePoint Server 2010 SP1, SharePoint Server 2010 SP2, SharePoint Foundation 2010 SP1, and SharePoint Foundation 2010 SP2.
CVE-2013-3180 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Yes, CVE-2013-3180 can be exploited remotely via crafted POST requests.