Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
BID:100723
CVE-2017-8758 |Info
Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
| Bugtraq ID: | 100723 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-8758 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Cem Onat Karagun Kocaeli University |
| Vulnerable: |
Microsoft Exchange Server 2016 Cumulative Update 6 0 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
Microsoft Exchange Server is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Microsoft Exchange Server 2016 Cumulative Update 6 is vulnerable.
Microsoft Exchange Server is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Microsoft Exchange Server 2016 Cumulative Update 6 is vulnerable.
Solution / Fix
Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
References:
References:
- Microsoft Exchange Home Page (Microsoft)
- Microsoft Homepage (Microsoft)
- CVE-2017-8758 | Microsoft Exchange Cross-Site Scripting Vulnerability (Microsoft)