CVE-2017-0195 is a cross-site scripting (XSS) vulnerability affecting Microsoft Excel Services in SharePoint Server 2010, Excel Web Apps 2010, Office Web Apps 2010 and 2013, and Office Online Server. This vulnerability allows remote attackers to execute scripts with local user privileges through a specially crafted request. With a CVSS score of 5.4 (Medium), it requires user interaction and low privileges, but can lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or Metasploit modules, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_web_app:2010:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.