Cross-Site Scripting Vulnerability in Microsoft SharePoint Server
CVE-2019-1033

5.4MEDIUM

What is CVE-2019-1033?

A cross-site scripting vulnerability exists in Microsoft SharePoint Server which fails to properly sanitize specially crafted web requests. This flaw could allow an attacker to execute arbitrary scripts in the context of a user’s session, potentially compromising sensitive information or enabling additional attacks against the user. Organizations utilizing this version of SharePoint Server should implement appropriate security measures to mitigate potential exploitation.

Affected Version(s)

Microsoft Project Server 2010 Service Pack 2 Unknown 13.0.0.0

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0

Microsoft SharePoint Foundation 2013 Service Pack 1 x64-based Systems 15.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.