CVE-2014-6326

Microsoft Exchange Server 2013 SP1-CU6 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6325.

References (1)

Core 1
Core References

Scores

EPSS 0.0872
EPSS Percentile 94.6%

Details

CWE
CWE-79
Status published
Products (1)
microsoft/exchange_server 2013 cumulative_update_6 (2 CPE variants)
Published Dec 11, 2014
Tracked Since Feb 18, 2026