Microsoft Project Server vulnerabilities
24 known vulnerabilities affecting microsoft/project_server.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM9
Vulnerabilities
Page 2 of 2
CVE-2019-1036P4MEDIUMCVSS 5.4v20102019-06-12
CVE-2019-1036 [MEDIUM] CWE-79 CVE-2019-1036: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1031P4MEDIUMCVSS 5.4v20102019-06-12
CVE-2019-1031 [MEDIUM] CWE-79 CVE-2019-1031: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-0954P4MEDIUMCVSS 5.4v20132020-04-15
CVE-2020-0954 [MEDIUM] CVE-2020-0954: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933,
nvd
CVE-2015-1640P4MEDIUMCVSS 4.3v2010v20132015-04-14
CVE-2015-1640 [MEDIUM] CWE-79 CVE-2015-1640: Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows re
Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
nvd
← Previous2 / 2