First published: Tue Apr 14 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1653 has a severity rating of important as it allows for cross-site scripting attacks.
To fix CVE-2015-1653, apply the latest security updates provided by Microsoft for SharePoint Foundation and SharePoint Server.
CVE-2015-1653 allows attackers to perform cross-site scripting (XSS) attacks which can lead to malicious script injection.
CVE-2015-1653 affects Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Server 2013 SP1.
CVE-2015-1653 was disclosed in 2015 as part of the MS15-036 security bulletin.