cbcvebase.
CVE-2013-1290
published 2013-04-09

CVE-2013-1290: Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint…

PriorityP424low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
16.99%
96.7th percentile
Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftsharepoint_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.