First published: Thu Jan 17 2019(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2018-3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0646 is a Cross-site Scripting (XSS) vulnerability that exists in Team Foundation Server.
CVE-2019-0646 allows attackers to inject malicious scripts into web pages viewed by users of Team Foundation Server.
CVE-2019-0646 has a severity rating of medium (5.4).
To fix CVE-2019-0646, apply the necessary patch provided by Microsoft.
You can find more information about CVE-2019-0646 at the following references: [1] http://www.securityfocus.com/bid/106651 [2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0646