CVE-2013-3895: Microsoft Office Web Apps

Medium severity, CVSS 6.8. EPSS: 29.6% chance of exploitation in the next 30 days.

Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."

Affected products

  • Microsoft Office Web Apps: version 2010 only
  • Microsoft SharePoint Server: version 2007 only; version 2010 only; version 2013 only

Published 2013-10-09. Last modified 2026-06-16.