← Back

CVE-2014-1754

nvd nist
Published: May 14, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."

Affected (7)

4 products
Office Web Apps Server
Sharepoint Foundation
Sharepoint Server
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2013
Version 2013 sp1
Microsoft
Version 2013
Version 2013 sp1
Microsoft
Version 2013
Version 2013 sp1
Version 2013

References (6)

Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.