Vulnerability Name: | CVE-2020-0973 (CCN-178807) |
Assigned: | 2019-11-04 |
Published: | 2020-04-14 |
Updated: | 2020-04-17 |
Summary: | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0978.
|
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 5.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Cross-Site Scripting |
References: | Source: MITRE Type: CNA CVE-2020-0973
Source: XF Type: UNKNOWN ms-office-cve20200973-xss(178807)
Source: CCN Type: Microsoft Security TechCenter - April 2020 Microsoft Office SharePoint XSS Vulnerability
Source: N/A Type: Patch, Vendor Advisory N/A
|
Vulnerable Configuration: | Configuration 1: cpe:/a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2016:-:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* Denotes that component is vulnerable |
BACK |
microsoft sharepoint enterprise server 2013 sp1
microsoft sharepoint enterprise server 2016
microsoft sharepoint server 2010 sp2
microsoft sharepoint server 2019
microsoft sharepoint server 2010 sp1
microsoft sharepoint server 2010 sp2
microsoft sharepoint enterprise server 2016 -
microsoft sharepoint enterprise server 2013 sp1
microsoft sharepoint server 2019