vendor:
SharePoint Server
by:
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: SharePoint Server
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
Cross-Site Scripting Vulnerability in Microsoft SharePoint Server
The vulnerability exists due to the application's failure to properly sanitize user-supplied input. An attacker can exploit this vulnerability by injecting arbitrary script code in the browser of a user visiting the affected site. This can lead to potential information theft and other malicious activities.
Mitigation:
Apply the latest security patches provided by Microsoft. Avoid visiting untrusted websites and do not click on suspicious links.