Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2019-1137

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

  • Published: Jul 15, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-1137
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
microsoft / exchange_server 2013-cumulative_update_7 2013-cumulative_update_7.x
microsoft / exchange_server 2013-cumulative_update_3 2013-cumulative_update_3.x
microsoft / exchange_server 2013-cumulative_update_17 2013-cumulative_update_17.x
microsoft / exchange_server 2013-cumulative_update_13 2013-cumulative_update_13.x
microsoft / exchange_server 2013-cumulative_update_8 2013-cumulative_update_8.x
microsoft / exchange_server 2013-sp1 2013-sp1.x
microsoft / exchange_server 2013-cumulative_update_12 2013-cumulative_update_12.x
microsoft / exchange_server 2013-cumulative_update_16 2013-cumulative_update_16.x
microsoft / exchange_server 2013-cumulative_update_2 2013-cumulative_update_2.x
microsoft / exchange_server 2013-cumulative_update_10 2013-cumulative_update_10.x
microsoft / exchange_server 2013-cumulative_update_11 2013-cumulative_update_11.x
microsoft / exchange_server 2013-cumulative_update_9 2013-cumulative_update_9.x
microsoft / exchange_server 2013-cumulative_update_14 2013-cumulative_update_14.x
microsoft / exchange_server 2013-cumulative_update_6 2013-cumulative_update_6.x
microsoft / exchange_server 2013-cumulative_update_18 2013-cumulative_update_18.x
microsoft / exchange_server 2013-cumulative_update_19 2013-cumulative_update_19.x
microsoft / exchange_server 2013-cumulative_update_20 2013-cumulative_update_20.x
microsoft / exchange_server 2013-cumulative_update_21 2013-cumulative_update_21.x
microsoft / exchange_server 2013-cumulative_update_22 2013-cumulative_update_22.x
microsoft / exchange_server 2013-cumulative_update_23 2013-cumulative_update_23.x
microsoft / exchange_server 2013-cumulative_update_1 2013-cumulative_update_1.x
microsoft / exchange_server 2013-cumulative_update_15 2013-cumulative_update_15.x
microsoft / exchange_server 2013-cumulative_update_5 2013-cumulative_update_5.x
microsoft / exchange_server 2013 2013.x
microsoft / exchange_server 2016-cumulative_update_6 2016-cumulative_update_6.x
microsoft / exchange_server 2016-cumulative_update_1 2016-cumulative_update_1.x
microsoft / exchange_server 2016-cumulative_update_5 2016-cumulative_update_5.x
microsoft / exchange_server 2016-cumulative_update_2 2016-cumulative_update_2.x
microsoft / exchange_server 2016-cumulative_update_7 2016-cumulative_update_7.x
microsoft / exchange_server 2016-cumulative_update_8 2016-cumulative_update_8.x
microsoft / exchange_server 2016-cumulative_update_9 2016-cumulative_update_9.x
microsoft / exchange_server 2016-cumulative_update_10 2016-cumulative_update_10.x
microsoft / exchange_server 2016-cumulative_update_11 2016-cumulative_update_11.x
microsoft / exchange_server 2016-cumulative_update_12 2016-cumulative_update_12.x
microsoft / exchange_server 2016-cumulative_update_13 2016-cumulative_update_13.x
microsoft / exchange_server 2016 2016.x
microsoft / exchange_server 2016-cumulative_update_3 2016-cumulative_update_3.x
microsoft / exchange_server 2016-cumulative_update_4 2016-cumulative_update_4.x
microsoft / exchange_server 2019-cumulative_update_1 2019-cumulative_update_1.x
microsoft / exchange_server 2019-cumulative_update_2 2019-cumulative_update_2.x
microsoft / exchange_server 2019 2019.x