CVE-2012-2520 describes a Cross-site Scripting (XSS) vulnerability, dubbed "HTML Sanitization Vulnerability," affecting multiple Microsoft products including InfoPath, Communicator, Lync, SharePoint, Groove Server, Windows SharePoint Services, SharePoint Foundation, and Office Web Apps. This flaw allows remote attackers to inject arbitrary web script or HTML through a crafted string. With a CVSS score of 4.3, it is a medium-severity vulnerability requiring medium attack complexity and resulting in partial integrity impact, but no confidentiality or availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:groove_server:2010:sp1:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:infopath:2007:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:infopath:2010:sp1:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.