CVE-2015-6039: XSS
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Office Marketplace instance, aka "Microsoft SharePoint Security Feature Bypass Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6039?
CVE-2015-6039 is rated as important, indicating that it poses a notable risk to affected systems.
How do I fix CVE-2015-6039?
To mitigate CVE-2015-6039, it is recommended to apply the security updates provided by Microsoft for SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1.
Who is affected by CVE-2015-6039?
CVE-2015-6039 affects Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 installations.
What type of vulnerability is CVE-2015-6039?
CVE-2015-6039 is a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web script or HTML.
Can CVE-2015-6039 be exploited remotely?
Yes, CVE-2015-6039 can be exploited by remote authenticated users who send crafted content to vulnerable SharePoint instances.