← All CVEs

CVE-2014-1754

medium · 4.3

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."

4.3
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2014-05-14
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
microsoftoffice_web_apps_server2013
microsoftoffice_web_apps_server2013
microsoftsharepoint_foundation2013
microsoftsharepoint_foundation2013
microsoftsharepoint_server2013
microsoftsharepoint_server2013
microsoftsharepoint_server_client_components_sdk2013

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-1754