CVE-2017-8569Cross-site Scripting in Corporation Microsoft Sharepoint Enterprise Server 2016

Severity
8.8HIGHNVD
EPSS
14.5%
top 5.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft_corporation/microsoft_sharepoint_enterprise_server_2016Microsoft SharePoint Enterprise Server 2016

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hq49-pqh6-q532: Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affe2022-05-13
CVEList
CVE-2017-8569: Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affe2017-07-11

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Elevation of Privilege Vulnerability2017-07-11

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - July 20172017-07-11
CVE-2017-8569 — Cross-site Scripting | cvebase