CVE-2015-2532: XSS
Published Sep 9, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability."
Affected Software
1 affected component
Microsoft Lync Server=2013
Event History
Sep 9, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2532?
CVE-2015-2532 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-2532?
To fix CVE-2015-2532, apply the security updates provided by Microsoft for Lync Server 2013.
3
What type of vulnerability is CVE-2015-2532?
CVE-2015-2532 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2015-2532?
CVE-2015-2532 affects users of Microsoft Lync Server 2013.
5
Can CVE-2015-2532 lead to information disclosure?
Yes, CVE-2015-2532 can allow remote attackers to inject scripts that could lead to information disclosure.