CVE-2017-0107Cross-site Scripting in Corporation Sharepoint

Severity
6.1MEDIUMNVD
EPSS
2.3%
top 15.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5hjr-r56j-5m47: Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Micr2022-05-17
CVEList
CVE-2017-0107: Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Micr2017-03-17

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Elevation of Privilege Vulnerability2017-03-14
CVE-2017-0107 — Cross-site Scripting | cvebase