Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-28288
8.1HIGH
Key Information:
Summary
A spoofing vulnerability in Microsoft SharePoint Server could allow an attacker to deceive users into believing they are interacting with a legitimate system. This flaw highlights the importance of implementing proper validation and security measures to protect sensitive information and maintain user trust.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1 x64-based Systems 15.0.0 < 15.0.5545.1000
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5391.1000
Microsoft SharePoint Foundation 2013 Service Pack 1 x64-based Systems 15.0.0 < 15.0.5545.1000
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved