Published: 2020-02-11

Description:
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka ‘Microsoft Office SharePoint XSS Vulnerability’. This CVE ID is unique from CVE-2020-0693.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’))

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore

3.5/10

2.9/10

6.8/10

Exploit range
Attack complexity
Authentication

Remote

Medium

Single time

Confidentiality impact
Integrity impact
Availability impact

None

Partial

None

 References:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0694

closedb();
?>


Copyright 2020, cxsecurity.com

 



Source link

Write a comment:
*

Your email address will not be published.