CVE-2020-1523
—CVSS 3.1
8.9 high
EPSS
2%p82
Published
()
Modified
Description
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user. The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.
- Vendors
- microsoft
- Products
- sharepoint server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.