← All CVEs

CVE-2015-2522

low · 3.5

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."

3.5
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2015-09-09
Published

AV:N/AC:M/Au:S/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
microsoftsharepoint_foundation2013

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-2522