CVE-2018-8578
published 2018-11-14CVE-2018-8578: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages…
PriorityP423medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
4.84%
91.0th percentile
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc4.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Information Disclosure Vulnerability
vendor_msrc·2018-11-13·CVSS 4.3
CVE-2018-8578 [MEDIUM] Microsoft SharePoint Information Disclosure Vulnerability
Microsoft SharePoint Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.
To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability.
The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Personally Identif
GHSA
GHSA-xj2f-r9jm-5w6p: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web
ghsa_unreviewed·2022-05-13
CVE-2018-8578 [MEDIUM] GHSA-xj2f-r9jm-5w6p: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105832http://www.securitytracker.com/id/1042133https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8578http://www.securityfocus.com/bid/105832http://www.securitytracker.com/id/1042133https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8578
2018-11-14
Published