CVE-2015-1633
Microsoft SharePoint Foundation and Server - Cross-Site Scripting
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-022
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031895
Scores
EPSS
0.0688
EPSS Percentile
93.4%
Details
CWE
CWE-79
Status
published
Products (4)
microsoft/sharepoint_foundation
2010 sp2
microsoft/sharepoint_foundation
2013 (2 CPE variants)
microsoft/sharepoint_server
2010 sp2
microsoft/sharepoint_server
2013 (2 CPE variants)
Published
Mar 11, 2015
Tracked Since
Feb 18, 2026