cbcvebase.
CVE-2018-8580
published 2018-12-12

CVE-2018-8580: An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search…

PriorityP276medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.04%
89.5th percentile
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint
microsoftmicrosoft_sharepoint
microsoftmicrosoft_sharepoint
microsoftsharepoint_server
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2013_service_pack_1
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2010_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered when a logged-in SharePoint user visits a malicious web page that induces the browser to issue search queries via standard browser functionality (cross-site search / CSRF variant). Monitor for SharePoint search requests originating from unexpected or external referrer origins.
  • Detect SharePoint search queries issued while the user is simultaneously authenticated to SharePoint and browsing an external/untrusted site. Look for search HTTP requests to SharePoint with suspicious or cross-origin Referer headers.
  • The attacker's goal is to infer document existence by observing whether targeted search queries return results or not. Anomalous patterns of repeated, targeted search queries from a single session — especially with no direct user interaction — may indicate exploitation.
  • ·Only certain modes of the SharePoint search function are vulnerable; not all search configurations are affected. Verify which search modes are in use before scoping detection.
  • ·Exploit status is assessed as 'Exploitation Unlikely' for both latest and older software releases, and there is no public exploit or known in-the-wild exploitation as of the advisory.

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck4.3MEDIUM
vendor_msrc4.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.