Cross-site Scripting Vulnerability in Team Foundation Server by Microsoft
CVE-2019-1076

5.4MEDIUM

What is CVE-2019-1076?

A Cross-site Scripting vulnerability exists in Microsoft Team Foundation Server due to improper sanitization of user input. This flaw allows attackers to inject malicious scripts into web pages viewed by other users. When an unsuspecting user interacts with a compromised page, these scripts can execute within their browser session, potentially leading to unauthorized actions or data breaches. Proper validation and sanitization measures need to be implemented to mitigate this security risk.

Affected Version(s)

Azure DevOps Server 2019.0.1

Team Foundation Server 2018 Update 3.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.