CVE-2019-0866 describes a Cross-site Scripting (XSS) vulnerability in Microsoft Azure DevOps Server and Team Foundation Server, stemming from improper sanitization of user-provided input. This medium-severity vulnerability (CVSS 6.1) requires user interaction (UI:R) and can lead to limited confidentiality and integrity impacts (C:L/I:L) if exploited. Attackers could leverage this via a network vector (AV:N) with low attack complexity (AC:L). There is no evidence of active exploitation, readily available exploit code in common frameworks like Metasploit or ExploitDB, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2019:*:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2015:4.2:*:*:*:*:*:* | ||
2017CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2017:3.1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2018:1.2:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:microsoft:team_foundation_server:2018:3.2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.