A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
2020-03-12T16:15:21.190
2025-02-28T21:15:15.327
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | exchange_server | 2016 | Yes |
Application | microsoft | exchange_server | 2016 | Yes |
Application | microsoft | exchange_server | 2019 | Yes |
Application | microsoft | exchange_server | 2019 | Yes |