PT-2019-1494 · Microsoft · Sharepoint Server+1

Published

2019-02-12

·

Updated

2019-03-06

·

CVE-2019-0670

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Foundation and Microsoft SharePoint Enterprise Server (affected versions not specified)
Description The issue is related to errors in parsing HTTP content of web pages in Microsoft SharePoint. This can allow a remote attacker to conduct phishing attacks and gain access to protected information using a specially crafted URI. An attacker who successfully exploits this issue could trick a user by redirecting them to a specially crafted website, which could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. To exploit the issue, the user must click a specially crafted URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00936
CVE-2019-0670

Affected Products

Sharepoint Server
Sharepoint Foundation