Elevation of Privilege Vulnerability in Microsoft SharePoint Server
CVE-2018-8156
5.4MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 9 May 2018
Summary
A vulnerability exists in Microsoft SharePoint Server that allows an attacker to exploit inadequate request sanitization. A specially crafted web request can lead to an elevation of privilege, granting unauthorized access to sensitive information or capabilities on the affected SharePoint server. This issue underscores the importance of ensuring secure configurations and prompt updates to protect against potential exploits.
Affected Version(s)
Microsoft Project Server 2010 Service Pack 2
Microsoft Project Server 2013 Service Pack 1
Microsoft SharePoint Enterprise Server 2016
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved