Description
A cross-site scripting and elevation of privilege vulnerability exists in SharePoint that allows attacker-controlled JavaScript to run in the context of the user clicking a link. This is an elevation of privilege vulnerability as it allows an anonymous attacker to potentially issue SharePoint commands in the context of an authenticated user on the site.
Remediation
Upgrade SharePoint to the latest version.
References
Related Vulnerabilities
WordPress Plugin Ultimate Profile Builder By CMSHelpLive Multiple Vulnerabilities (2.3.3)
WordPress Plugin Ultimate TinyMCE 'swfupload.swf' Cross-Site Scripting (3.5)
WordPress Plugin Variation Swatches for WooCommerce Cross-Site Scripting (2.1.1)
WordPress Plugin WangGuard Multiple Vulnerabilities (1.7.2)
WordPress Plugin WP Custom Fields Search Cross-Site Scripting (1.2.34)