CVE-2017-0255Cross-site Scripting in Corporation Microsoft Office

Severity
5.4MEDIUMNVD
EPSS
1.2%
top 21.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMar 22

Description

Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5microsoft_corporation/microsoft_officeMicrosoft SharePoint Foundation 2013 SP1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9r5f-fvq3-4j7x: Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web req2022-05-17
CVEList
CVE-2017-0255: Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web req2017-05-12

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Elevation of Privilege Vulnerability2017-05-09

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - May 20172017-05-10

💬Community

1
HackerOne
Reflective Cross Site Scripting (XSS) on ███████/Pages2024-03-22
CVE-2017-0255 — Cross-site Scripting | cvebase