Vulnerability Name: | CVE-2020-0923 (CCN-178785) |
Assigned: | 2019-11-04 |
Published: | 2020-04-14 |
Updated: | 2020-04-17 |
Summary: | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0973, CVE-2020-0978.
|
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 5.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Cross-Site Scripting |
References: | Source: MITRE Type: CNA CVE-2020-0923
Source: XF Type: UNKNOWN ms-office-cve20200923-xss(178785)
Source: CCN Type: Microsoft Security TechCenter - April 2020 Microsoft Office SharePoint XSS Vulnerability
Source: N/A Type: Patch, Vendor Advisory N/A
|
Vulnerable Configuration: | Configuration 1: cpe:/a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2016:-:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* Denotes that component is vulnerable |
BACK |