Описание
Azure App Service Cross-site Scripting Vulnerability
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the App Service, which will get executed in the context of the user every time a user visits the compromised page.
The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, execute malicious code, and use the victim's identity to take actions on the site on behalf of the user, such as change permissions and delete content.
The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Azure App Service on Azure Stack |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
DOS
EPSS
Связанные уязвимости
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
Уязвимость компонента Azure App Services программной платформы Azure Stack, позволяющая нарушителю внедрить произвольный код в загружаемую пользователем веб-страницу
EPSS