Microsoft Exchange Server Vulnerability Fixed (XSS) (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- XSS vulnerability fixed in Exchange Server
- Allows script injection and spoofing
- Root cause: improper input sanitization
"The Dutch NCSC reported a resolved vulnerability in Microsoft Exchange Server. The issue is a cross-site scripting (XSS) flaw due to improper input sanitization. An attacker can inject malicious scripts and perform spoofing attacks over the network. The fix addresses inadequate handling of user input in web page generation."
no comments yet.