CVE-2017-11876
Severity
8.8HIGH
EPSS
1.0%
top 23.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15
Latest updateMay 17
Description
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
▶CVEListV5microsoft_corporation/microsoft_serverMicrosoft Project Server 2013, Microsoft SharePoint Enterprise Server 2016
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-hc3g-h2rv-xpmc: Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not↗2022-05-17
CVEList▶
CVE-2017-11876: Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not↗2017-11-15