CVE-2020-0903

Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka Microsoft Exchange Server Spoofing Vulnerability.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.732

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Server Spoofing Vulnerability For Exchange Server 2019 CU4 (KB4540123)Windows
Microsoft Exchange Server Spoofing Vulnerability For Exchange Server 2019 CU3 (KB4540123)Windows
Microsoft Exchange Server Spoofing Vulnerability For Exchange Server 2016 CU15 (KB4540123)Windows
Microsoft Exchange Server Spoofing Vulnerability For Exchange Server 2016 CU14 (KB4540123)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-28580Security Update For Exchange Server 2019 CU4 (KB4540123)
PATCH-28581Security Update For Exchange Server 2019 CU3 (KB4540123)
PATCH-28582Security Update For Exchange Server 2016 CU15 (KB4540123)
PATCH-28583Security Update For Exchange Server 2016 CU14 (KB4540123)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234