Cross-Site Scripting Vulnerability in Microsoft ASP.NET SignalR and Visual Studio Team Foundation Server
CVE-2013-5042

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
11 December 2013

Summary

A Cross-Site Scripting (XSS) vulnerability exists in Microsoft ASP.NET SignalR versions 1.1.x prior to 1.1.4 and 2.0.x prior to 2.0.1, as well as in Visual Studio Team Foundation Server 2013. This flaw allows remote attackers to inject malicious web scripts or HTML into web applications using crafted Forever Frame transport protocol data. Exploitation of this vulnerability can lead to unauthorized data exposure or manipulation, placing users and systems at risk.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.