CVE-2018-0799Cross-site Scripting in Corporation Microsoft Access

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 14

Description

Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5microsoft_corporation/microsoft_accessMicrosoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hg9c-qg74-469r: Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vu2022-05-14
CVEList
CVE-2018-0799: Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vu2018-01-10

📋Vendor Advisories

1
Microsoft
Microsoft Access Tampering Vulnerability2018-01-09
CVE-2018-0799 — Cross-site Scripting | cvebase