CVE-2019-0872 vulnerability in Microsoft Products
Published on May 16, 2019
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0979.
Products Associated with CVE-2019-0872
stack.watch emails you whenever new vulnerabilities are published in Microsoft Team Foundation Server or Microsoft Azure Devops Server. Just hit a watch button to start following.
Affected Versions
Microsoft Team Foundation Server:- Version 2017 Update 3.1 is affected.
- Version Update 1.2 is affected.
- Version Update 3.2 is affected.
- Version 2019 is affected.
- Version Update 4.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.