Cross-Site Scripting Vulnerability in Microsoft ASP.NET SignalR and Visual Studio Team Foundation Server
CVE-2013-5042
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 11 December 2013
Summary
A Cross-Site Scripting (XSS) vulnerability exists in Microsoft ASP.NET SignalR versions 1.1.x prior to 1.1.4 and 2.0.x prior to 2.0.1, as well as in Visual Studio Team Foundation Server 2013. This flaw allows remote attackers to inject malicious web scripts or HTML into web applications using crafted Forever Frame transport protocol data. Exploitation of this vulnerability can lead to unauthorized data exposure or manipulation, placing users and systems at risk.
References
EPSS Score
10% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved