Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-28288

8.1HIGH

Summary

A spoofing vulnerability in Microsoft SharePoint Server could allow an attacker to deceive users into believing they are interacting with a legitimate system. This flaw highlights the importance of implementing proper validation and security measures to protect sensitive information and maintain user trust.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2013 Service Pack 1 x64-based Systems 15.0.0 < 15.0.5545.1000

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5391.1000

Microsoft SharePoint Foundation 2013 Service Pack 1 x64-based Systems 15.0.0 < 15.0.5545.1000

References

EPSS Score

14% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.