This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2020-0795.
2020-03-12T16:15:20.643
2025-02-28T21:15:14.830
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | sharepoint_enterprise_server | 2016 | Yes |
Application | microsoft | sharepoint_foundation | 2010 | Yes |
Application | microsoft | sharepoint_foundation | 2013 | Yes |
Application | microsoft | sharepoint_server | 2019 | Yes |