Cross-Site Scripting Vulnerability in Microsoft SharePoint Server
CVE-2020-0954

5.4MEDIUM

Summary

A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint Server due to improper sanitization of specially crafted web requests. This flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, data theft, or unauthorized actions performed on behalf of an unsuspecting user. It is crucial for organizations using affected versions of SharePoint Server to apply available security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Microsoft Project Server 2013 Service Pack 1 (64-bit edition)

Microsoft SharePoint Enterprise Server 2016

Microsoft SharePoint Server 2019

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.