60
CVE-2016-0011
—CVSS 3.0
5.4 medium
EPSS
5%p92
Published
()
Modified
Description
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
- Vendors
- microsoft
- Products
- sharepoint server, sharepoint foundation
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N