CVE-2012-0145Cross-site Scripting in Microsoft Sharepoint Foundation

Severity
4.3MEDIUMNVD
EPSS
35.9%
top 2.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 4

Description

Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-r6rm-h4xm-xg47: Cross-site scripting (XSS) vulnerability in wizardlist2022-05-04
CVEList
CVE-2012-0145: Cross-site scripting (XSS) vulnerability in wizardlist2012-02-14

🕵️Threat Intelligence

1
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 12
CVE-2012-0145 — Cross-site Scripting in Microsoft | cvebase