← Vulnerability feed

Vulnerability record · CVE-2015-2531 · published 9 September 2015

CVE-2015-2531: Microsoft lync server cross-site scripting vulnerability

Microsoft · Lync Server

Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability."

4.3 CVSS 2.0 Medium EPSS 11% · top 4.3% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2531 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2023-41763Microsoft Skype for Business Server SSRF Elevation of PrivilegeCVE-2023-41763 is a server-side request forgery (CWE-918) flaw in Microsoft Skype for Business Server, rated by Microsoft as an elevation of privileg…KEVEPSS 90%analysed9.8CVE-2026-66302Microsoft skype for business server vulnerabilityExternal control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.EPSS 0.97%9.3CVE-2013-1302Microsoft lync memory buffer overflow vulnerabilityMicrosoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote att…EPSS 22%8.3CVE-2026-69646Microsoft skype for business server improper verification of cryptographic signature vulnerabilityImproper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.EPSS 0.32%7.5CVE-2026-66307Microsoft skype for business server vulnerabilityInteger underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.EPSS 1.2%7.5CVE-2026-66304Microsoft skype for business server server-side request forgery (ssrf) vulnerabilityServer-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.EPSS 0.97%7.2CVE-2023-36780Microsoft skype for business server untrusted search path vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.6%7.2CVE-2023-36786Microsoft skype for business server vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2015-2531), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.