CVE-2015-6039

Microsoft SharePoint Server 2013 SP1-SharePoint Foundation 2013 SP1...

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Office Marketplace instance, aka "Microsoft SharePoint Security Feature Bypass Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033804

Scores

EPSS 0.0906
EPSS Percentile 94.8%

Details

CWE
CWE-79
Status published
Products (2)
microsoft/sharepoint_foundation 2013 sp1
microsoft/sharepoint_server 2013 sp1
Published Oct 14, 2015
Tracked Since Feb 18, 2026