PT-2018-1079 · Microsoft · Sharepoint Server+1
Ashar Javed
·
Published
2018-01-09
·
Updated
2019-10-03
·
CVE-2018-0789
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Foundation version 2010
Microsoft SharePoint Server versions 2013 through 2016
Description
The issue is related to the handling of web requests and insufficient access control, allowing an elevation of privilege. An authenticated attacker could exploit this by sending a specially crafted HTTP request to an affected server, potentially leading to cross-site scripting attacks. This could enable the attacker to read unauthorized content, use the victim's identity to change permissions, delete content, and inject malicious content into the user's browser.
Recommendations
For Microsoft SharePoint Foundation 2010, update to a version that includes the fix for this issue.
For Microsoft SharePoint Server 2013, apply the necessary patch or update to resolve the vulnerability.
For Microsoft SharePoint Server 2016, consider disabling the handling of specially crafted web requests until a patch is available, and apply the necessary update once it is released.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Foundation
Sharepoint Server