CVE-2010-3243

MEDIUM

Microsoft Internet Explorer 8 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."

Scores

CVSS v3 4.3
EPSS 0.3807
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-79
Status draft

Affected Products (5)

microsoft/sharepoint_server
microsoft/sharepoint_server
microsoft/sharepoint_services
microsoft/sharepoint_services
microsoft/internet_explorer

Timeline

Published Oct 13, 2010
Tracked Since Feb 18, 2026