CVE-2019-0777 describes a Cross-site Scripting (XSS) vulnerability in Microsoft Team Foundation Server, stemming from improper sanitization of user-provided input. With a CVSS score of 5.4 (MEDIUM), this vulnerability requires user interaction (UI:R) and low privileges (PR:L) for an attacker to achieve limited confidentiality and integrity impacts (C:L/I:L). While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2017CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2017:3.1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2018:1.2:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2018:3.2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.