PT-2020-4314 · Microsoft · Sharepoint Server+1

Published

2020-10-13

·

Updated

2023-12-31

·

CVE-2020-16944

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft SharePoint Server (affected versions not specified)
Description: This issue occurs when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server. An authenticated attacker could exploit this by sending a specially crafted request, allowing them to perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. These attacks could enable the attacker to read unauthorized content, use the victim's identity to take actions on the SharePoint site, change permissions, delete content, steal sensitive information, and inject malicious content in the victim's browser. For this issue to be exploited, a user must click a specially crafted URL that takes them to a targeted SharePoint Web App site.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Spoofing

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04811
CVE-2020-16944

Affected Products

Sharepoint Server
Sharepoint Foundation