CVE-2013-1289

EXPLOITED

Microsoft SharePoint <2010 SP1 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-1289 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/ncas/alerts/TA13-100A
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16599

Scores

EPSS 0.1543
EPSS Percentile 96.5%

Details

VulnCheck KEV 2013-04-09
CWE
CWE-79
Status published
Products (5)
microsoft/groove_server 2010 sp1
microsoft/infopath 2010 sp1 (2 CPE variants)
microsoft/office_web_apps 2010 sp1
microsoft/sharepoint_foundation 2010 sp1
microsoft/sharepoint_server 2010 sp1
Published Apr 09, 2013
Tracked Since Feb 18, 2026