CVE-2018-8580
published 2018-12-12CVE-2018-8580: An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search…
PriorityP276medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.04%
89.5th percentile
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint | — | — |
| microsoft | microsoft_sharepoint | — | — |
| microsoft | microsoft_sharepoint | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered when a logged-in SharePoint user visits a malicious web page that induces the browser to issue search queries via standard browser functionality (cross-site search / CSRF variant). Monitor for SharePoint search requests originating from unexpected or external referrer origins. ↗
- →Detect SharePoint search queries issued while the user is simultaneously authenticated to SharePoint and browsing an external/untrusted site. Look for search HTTP requests to SharePoint with suspicious or cross-origin Referer headers. ↗
- →The attacker's goal is to infer document existence by observing whether targeted search queries return results or not. Anomalous patterns of repeated, targeted search queries from a single session — especially with no direct user interaction — may indicate exploitation. ↗
- ·Only certain modes of the SharePoint search function are vulnerable; not all search configurations are affected. Verify which search modes are in use before scoping detection. ↗
- ·Exploit status is assessed as 'Exploitation Unlikely' for both latest and older software releases, and there is no public exploit or known in-the-wild exploitation as of the advisory. ↗
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck4.3MEDIUM
vendor_msrc4.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Information Disclosure Vulnerability
vendor_msrc·2018-12-11·CVSS 4.3
CVE-2018-8580 [MEDIUM] Microsoft SharePoint Information Disclosure Vulnerability
Microsoft SharePoint Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).
When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user. While the attacker can’t access the search results or documents as such, the attacker can determine whether the query did return results or not, and thus by issuing targeted queries discover facts about documents that are searchable for the logged-in user.
The security update addresses
GHSA
GHSA-phxm-v2jv-4gg8: An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site
ghsa_unreviewed·2022-05-13
CVE-2018-8580 [MEDIUM] CWE-200 GHSA-phxm-v2jv-4gg8: An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
VulnCheck
Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor
vulncheck·2018·CVSS 4.3
CVE-2018-8580 [MEDIUM] Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor
Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Affected: Microsoft SharePoint
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.tenable.com/blog/daisy-chaining-how-vulnerabilities-can-be-greater-than-the-sum-of-their-parts
No detection rules found.
No public exploits indexed.
2018-12-12
Published
Exploited in the wild