CVE-2015-2531: XSS
Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2531?
CVE-2015-2531 has a medium severity rating due to its potential for attacks that can lead to information disclosure.
How do I fix CVE-2015-2531?
To fix CVE-2015-2531, apply the security updates released by Microsoft for both Microsoft Lync Server 2013 and Skype for Business Server 2015.
Who is affected by CVE-2015-2531?
CVE-2015-2531 affects users of Microsoft Lync Server 2013 and Skype for Business Server 2015.
What type of vulnerability is CVE-2015-2531?
CVE-2015-2531 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
Can CVE-2015-2531 lead to data breaches?
Yes, CVE-2015-2531 can potentially lead to data breaches through the misuse of injected scripts.