CVE-2015-2522
low · 3.5Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."
3.5
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2015-09-09
Published
AV:N/AC:M/Au:S/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | sharepoint_foundation | 2013 |
Check a specific version with /api/v1/cve/match.
References
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.securitytracker.com/id/1033489
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.securitytracker.com/id/1033489
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2522