First published: Thu Nov 10 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7251 has a severity rating of 'Medium' due to its potential for remote exploitation.
To fix CVE-2016-7251, you should apply the latest security updates provided by Microsoft for SQL Server 2016.
CVE-2016-7251 affects all installations of Microsoft SQL Server 2016 that utilize the MDS API.
CVE-2016-7251 is classified as a Cross-site scripting (XSS) vulnerability.
An attacker exploiting CVE-2016-7251 can inject arbitrary web scripts or HTML into the MDS API, potentially leading to unauthorized actions.