CVE-2017-8514
published 2017-06-15CVE-2017-8514: An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft…
PriorityP426medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
3.03%
86.0th percentile
An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft_corporation | microsoft_sharepoint | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc5.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Reflective XSS Vulnerability
vendor_msrc·2017-06-13·CVSS 5.4
CVE-2017-8514 [MEDIUM] Microsoft SharePoint Reflective XSS Vulnerability
Microsoft SharePoint Reflective XSS Vulnerability
Description: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.
An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the victim, such as change permissions, delete content, steal sensitive information (such as brows
GHSA
GHSA-66w4-rgqr-wwr6: An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Micros
ghsa_unreviewed·2022-05-14
CVE-2017-8514 [MEDIUM] CWE-79 GHSA-66w4-rgqr-wwr6: An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Micros
An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability".
Suricata
ET EXPLOIT Possible SharePoint XSS (CVE-2017-8514) Inbound
suricata·2017-06-19·CVSS 5.4
CVE-2017-8514 [MEDIUM] ET EXPLOIT Possible SharePoint XSS (CVE-2017-8514) Inbound
ET EXPLOIT Possible SharePoint XSS (CVE-2017-8514) Inbound
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Possible SharePoint XSS (CVE-2017-8514) Inbound"; flow:established,to_server; http.uri; content:"FollowSite="; nocase; fast_pattern; content:"SiteName="; nocase; content:"-confirm"; nocase; distance:0; reference:url,respectxss.blogspot.fr/2017/06/a-look-at-cve-2017-8514-sharepoints.html; classtype:attempted-user; sid:2024412; rev:4; metadata:affected_product HTTP_Server, attack_target Server, created_at 2017_06_19, cve CVE_2017_8514, deployment Internal, performance_impact Moderate, confidence Medium, signature_severity Major, updated_at 2024_03_07;)
No public exploits indexed.
http://www.securityfocus.com/bid/98831http://www.securitytracker.com/id/1038663https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8514http://www.securityfocus.com/bid/98831http://www.securitytracker.com/id/1038663https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8514
2017-06-15
Published