PT-2019-3187 · Microsoft · Sharepoint Server+1

David Cioccia

+1

·

Published

2019-09-10

·

Updated

2019-09-24

·

CVE-2019-1262

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Foundation (affected versions not specified) Microsoft SharePoint Server (affected versions not specified)
Description The issue is related to a lack of input sanitization, which can lead to cross-site scripting (XSS) attacks. An attacker could exploit this by sending a specially crafted web request to an affected server. Successful exploitation could allow the attacker to perform actions such as reading unauthorized content, using the victim's identity to change permissions or delete content, and injecting malicious content into the user's browser.
Recommendations For Microsoft SharePoint Foundation, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Microsoft SharePoint Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03176
CVE-2019-1262

Affected Products

Sharepoint Foundation
Sharepoint Server