XSS Vulnerability in Microsoft Internet Explorer and SharePoint Products
CVE-2010-3324

Currently unrated

What is CVE-2010-3324?

A vulnerability exists in the toStaticHTML function of Microsoft Internet Explorer 8 and the SafeHTML function in multiple Microsoft SharePoint products. This flaw allows remote attackers to exploit the HTML sanitization process by crafting a malicious use of the CSS @import rule, circumventing the built-in XSS protection mechanisms. As a result, attackers may conduct XSS attacks, potentially compromising user data and system integrity.

References

EPSS Score

43% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2010-3324 : XSS Vulnerability in Microsoft Internet Explorer and SharePoint Products