CVE-2015-1640: XSS
Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1640?
CVE-2015-1640 is rated as important due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2015-1640?
To fix CVE-2015-1640, install the security update provided by Microsoft for both Project Server 2010 SP2 and 2013 SP1.
What software versions are affected by CVE-2015-1640?
CVE-2015-1640 affects Microsoft Project Server versions 2010 SP2 and 2013 SP1.
What type of vulnerability is CVE-2015-1640?
CVE-2015-1640 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts into web pages.
Can I mitigate the risk of CVE-2015-1640 if I cannot update immediately?
Mitigating the risk of CVE-2015-1640 includes limiting user input and sanitizing any data that will be displayed in web pages.