PT-2011-3454 · Microsoft · Office Sharepoint Server 2010+5

Published

2011-09-15

·

Updated

2018-10-12

·

CVE-2011-1893

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office SharePoint Server 2010 Windows SharePoint Services 2.0 Windows SharePoint Services 3.0 SP2 SharePoint Foundation 2010
Description A cross-site scripting vulnerability exists, allowing remote attackers to inject arbitrary web script or HTML via the URI. This issue also involves information disclosure and elevation of privilege, where JavaScript encoded in a specially crafted URL can be reflected back to the user, enabling an attacker to issue commands in the context of the authenticated user on a targeted site.
Recommendations For Microsoft Office SharePoint Server 2010, update to a version that includes the fix for this issue. For Windows SharePoint Services 2.0, consider disabling the use of specially crafted URLs until a patch is available. For Windows SharePoint Services 3.0 SP2, restrict access to the affected pages to minimize the risk of exploitation. For SharePoint Foundation 2010, avoid using JavaScript encoded in URLs in the affected API endpoints until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1893

Affected Products

Office Sharepoint Server 2010
Sharepoint Foundation 2010
Sharepoint Foundation
Sharepoint Server
Windows Sharepoint Services 2.0
Windows Sharepoint Services 3.0