The host is installed with Lync Server 2013 or 2010 and is prone to a cross-site scripting (XSS) vulnerability. A flaw is present in the application, which fails to properly handle a crafted URL. Successful exploitation could allow attackers to inject arbitrary web script or HTML.