Published: 2020-05-21

Description:
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka ‘Microsoft Office SharePoint XSS Vulnerability’. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1101.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’))

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore

4.3/10

2.9/10

8.6/10

Exploit range
Attack complexity
Authentication

Remote

Medium

No required

Confidentiality impact
Integrity impact
Availability impact

None

Partial

None

 References:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1106

closedb();
?>


Copyright 2020, cxsecurity.com

 



Source link

Write a comment:
*

Your email address will not be published.