Elevation of Privilege Vulnerability in Microsoft SharePoint Server
CVE-2018-8156

5.4MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 May 2018

Summary

A vulnerability exists in Microsoft SharePoint Server that allows an attacker to exploit inadequate request sanitization. A specially crafted web request can lead to an elevation of privilege, granting unauthorized access to sensitive information or capabilities on the affected SharePoint server. This issue underscores the importance of ensuring secure configurations and prompt updates to protect against potential exploits.

Affected Version(s)

Microsoft Project Server 2010 Service Pack 2

Microsoft Project Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.