Outlook Web Access is a component of Exchange Server that allows for users to access their mail using a web browser. Outlook Web Access contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface. The vulnerability is due to a failure to properly detect and filter obfuscated script code. Successful exploitation may result in attacker supplied script code performing OWA actions as the victim.
Outlook Web Access is a component of Exchange Server that allows for users to access their mail using a web browser. Outlook Web Access contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface. The vulnerability is due to a failure to properly detect and filter obfuscated script code. Successful exploitation may result in attacker supplied script code performing OWA actions as the victim.