First published: Wed Oct 14 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Office Marketplace instance, aka "Microsoft SharePoint Security Feature Bypass Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6039 is rated as important, indicating that it poses a notable risk to affected systems.
To mitigate CVE-2015-6039, it is recommended to apply the security updates provided by Microsoft for SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1.
CVE-2015-6039 affects Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 installations.
CVE-2015-6039 is a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web script or HTML.
Yes, CVE-2015-6039 can be exploited by remote authenticated users who send crafted content to vulnerable SharePoint instances.