CVE Database
/

CVE-2019-1137

Back to search

CVE-2019-1137

Published: Jul 29, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

VendorProductVersions

Microsoft

Microsoft Exchange Server 2016

affected
Cumulative Update 12
affected
Cumulative Update 13

Microsoft

Microsoft Exchange Server 2019

affected
Cumulative Update 1
affected
Cumulative Update 2

Microsoft

Microsoft Exchange Server 2013

affected
Cumulative Update 23

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now