Reflective XSS Vulnerability in Microsoft SharePoint Server
CVE-2020-0795
5.4MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 March 2020
What is CVE-2020-0795?
This vulnerability occurs when Microsoft SharePoint Server fails to adequately sanitize specially crafted requests. An authenticated attacker can exploit this flaw by sending a malicious request to an affected SharePoint server. This can potentially allow the attacker to execute scripts in the context of the user’s session, leading to unauthorized access and manipulation of data, making it crucial for organizations to apply the necessary security updates.
Affected Version(s)
Microsoft Business Productivity Servers 2010 Service Pack 2
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1