CVE-2015-6037: XSS
Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka "Microsoft Office Web Apps XSS Spoofing Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6037?
CVE-2015-6037 is rated as important, indicating a substantial risk to affected systems.
How do I fix CVE-2015-6037?
To fix CVE-2015-6037, apply the latest security updates for Microsoft Excel Services and SharePoint as recommended by Microsoft.
Which versions are affected by CVE-2015-6037?
CVE-2015-6037 affects Microsoft Excel Services on SharePoint Server 2010 SP2, 2013 SP1, Office Web Apps 2010 SP2, and Excel Web App 2010 SP2.
What type of vulnerability is CVE-2015-6037?
CVE-2015-6037 is a Cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject web scripts.
Can CVE-2015-6037 affect user data?
Yes, CVE-2015-6037 can potentially allow attackers to manipulate and access user data through injected scripts.