Microsoft ASP.NET MVC Security Feature Bypass Vulnerability
Last Update Date:
15 Oct 2014 17:51
Release Date:
15 Oct 2014
3822
Views
RISK: Medium Risk
TYPE: Operating Systems - Application Platforms
A cross-site scripting (XSS) vulnerability exists in ASP.NET MVC that could allow an attacker to inject a client-side script into the user's web browser. The script could spoof content, disclose information, or take any action that the user could take on the site on behalf of the targeted user.
Impact
- Cross-Site Scripting
System / Technologies affected
- ASP.NET MVC 2.0
- ASP.NET MVC 3.0
- ASP.NET MVC 4.0
- ASP.NET MVC 5.0
- ASP.NET MVC 5.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-059
Vulnerability Identifier
Source
Related Link
Share with