Unrated severityNVD Advisory· Published Mar 11, 2015· Updated May 6, 2026
CVE-2015-1636
CVE-2015-1636
Description
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Affected products
4cpe:2.3:a:microsoft:sharepoint_foundation:2013:-:-:*:gold:*:*:*+ 1 more
- cpe:2.3:a:microsoft:sharepoint_foundation:2013:-:-:*:gold:*:*:*
- cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2013:-:-:*:gold:*:*:*+ 1 more
- cpe:2.3:a:microsoft:sharepoint_server:2013:-:-:*:gold:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.