Microsoft Exchange Server Autodiscover Cross-Site Scripting

medium Web App Scanning Plugin ID 113057

Synopsis

Microsoft Exchange Server Autodiscover Cross-Site Scripting

Description

Microsoft Exchange Server versions 2019 before cumulative update 11, 2016 before cumulative update 22 and 2013 before cumulative update 23 are affected by a cross-site scripting vulnerability through the `autodiscover/autodiscover.json` endpoint. By crafting a specific URL, an attacker could target any Exchange user and try conducting phishing attacks or performing arbitrary modification on the target application.

Solution

Apply cumulative update 11 for Exchange Server 2019, cumulative update 22 for Exchange Server 2016 and cumulative update 23 for Exchange Server 2013 as described on Microsoft website.

See Also

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41349

https://support.microsoft.com/en-gb/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-november-9-2021-kb5007409-7e1f235a-d41b-4a76-bcc4-3db90cd161e7

Plugin Details

Severity: Medium

ID: 113057

Type: remote

Published: 11/22/2021

Updated: 11/22/2021

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-41349

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS Score Source: CVE-2021-41349

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

CVE: CVE-2021-41349