ZeroHour

CVE-2018-8426

CVSS 3.0
5.4 medium
EPSS
2%p82
Published
()
Modified
Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.

Vendors
microsoft
Products
sharepoint enterprise server 2013, sharepoint enterprise server 2016, sharepoint server 2010
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.