CVE-2013-5042
Microsoft ASP.NET SignalR <1.1.4, 2.0.x <2.0.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."
Scores
EPSS
0.1041
EPSS Percentile
93.2%
Details
CWE
CWE-79
Status
published
Products (7)
microsoft/asp.net_signalr
microsoft/asp.net_signalr
microsoft/asp.net_signalr
microsoft/asp.net_signalr
microsoft/asp.net_signalr
microsoft/visual_studio_team_foundation_server
n/a/n/a
Published
Dec 11, 2013
Tracked Since
Feb 18, 2026