CVE-2013-5072

Microsoft Exchange <2013 CU3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

Scores

EPSS 0.0664
EPSS Percentile 91.1%

Details

CWE
CWE-79
Status published
Products (5)
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
n/a/n/a
Published Dec 11, 2013
Tracked Since Feb 18, 2026