CVE-2019-1262
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
- Affected products
- Sharepoint Foundation, Sharepoint Server
- Microsoft Sharepoint Foundation
- = 2013
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-09-11
CVE-2019-1262 at NVD
5 known exploits for CVE-2019-1262
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft SharePoint 2013 SP1 - (DestinationFolder) Persistant Cross-Site Scripting Vulnerability
Microsoft SharePoint 2013 SP1 - DestinationFolder Persistant Cross-Site Scripting
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
Microsoft SharePoint 2013 SP1 Cross Site Scripting
Microsoft SharePoint 2013 SP1 Stored XSS Vulnerability