CVE-2013-5042: XSS
Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5042?
CVE-2013-5042 is considered a moderate severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2013-5042?
To fix CVE-2013-5042, upgrade Microsoft ASP.NET SignalR to version 1.1.4 or 2.0.1, or update Visual Studio Team Foundation Server 2013 to a patched version.
Who is affected by CVE-2013-5042?
CVE-2013-5042 affects users of Microsoft ASP.NET SignalR versions 1.1.0 to 1.1.3 and 2.0.0, as well as Visual Studio Team Foundation Server 2013.
What types of attacks can CVE-2013-5042 enable?
CVE-2013-5042 can enable attackers to perform cross-site scripting attacks, allowing them to inject arbitrary scripts or HTML into web pages.
When was CVE-2013-5042 disclosed?
CVE-2013-5042 was disclosed in the context of Microsoft's security update MS13-103 released in December 2013.