CVE-2023-28288
published 2023-04-11CVE-2023-28288: Microsoft SharePoint Server Spoofing Vulnerability
PriorityP358high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EXPLOIT
EPSS
6.23%
92.8th percentile
Microsoft SharePoint Server Spoofing Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < 15.0.5545.1000 | 15.0.5545.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5391.1000 | 16.0.5391.1000 |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < 15.0.5545.1000 | 15.0.5545.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10397.20002 | 16.0.10397.20002 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.16130.20314 | 16.0.16130.20314 |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability
vendor_msrc·2023-04-11·CVSS 8.1
CVE-2023-28288 [HIGH] CWE-918 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
FAQ: I am running SharePoint Enterprise Server 2013 Service Pack 1. Do I need to install both updates that are listed for SharePoint Enterprise Server 2013 Service Pack 1?
No. The Cumulative update for SharePoint Server 2013 includes the update for Foundation Server 2013. Customers running SharePoint Server 2013 Service Pack 1 can install the cumulative update or the security update, which is the same update as for Foundation Server 2013.
Please note that this is a clarification of the existing servicing model for SharePoint Server 2013 and applies for all previous updates.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated and possess the p
GHSA
GHSA-vpjm-mmm2-rqq5: Microsoft SharePoint Server Spoofing Vulnerability
ghsa_unreviewed·2023-04-11
CVE-2023-28288 [MEDIUM] GHSA-vpjm-mmm2-rqq5: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
No detection rules found.
Trendmicro
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
blogs_trendmicro·2023-11-02
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
## Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
Learn about the Server Side Request Forgery (SSRF) vulnerability and fix.
By: Zero Day Initiative Nov 02, 2023 Read time: ( words)
Save to Folio
Server Side Request Forgery (SSRF) . This vulnerability class triggers a wide range of emotions and reactions, ranging from complete ignorance to panic. Though it is included in the OWASP Top 10 list of web application security risks, at times vendors tend to downplay it and not treat it seriously.
As usual, the truth lies somewhere in between. What appears to be SSRF may sometimes in fact be intended functionality. Even so, an attacker may be able to abuse that functionality to improperly disclose sensitive information, either from the application containing th
Trendmicro
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
blogs_trendmicro·2023-11-02
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
## Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
Learn about the Server Side Request Forgery (SSRF) vulnerability and fix.
By: Zero Day Initiative 2023/11/02 Read time: ( words)
Save to Folio
Server Side Request Forgery (SSRF) . This vulnerability class triggers a wide range of emotions and reactions, ranging from complete ignorance to panic. Though it is included in the OWASP Top 10 list of web application security risks, at times vendors tend to downplay it and not treat it seriously.
As usual, the truth lies somewhere in between. What appears to be SSRF may sometimes in fact be intended functionality. Even so, an attacker may be able to abuse that functionality to improperly disclose sensitive information, either from the application containing the
Trendmicro
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
blogs_trendmicro·2023-11-02
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
# Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
Learn about the Server Side Request Forgery (SSRF) vulnerability and fix.
By: Zero Day Initiative
2023/11/02
Read time: ( words)
Save to Folio
Server Side Request Forgery (SSRF). This vulnerability class triggers a wide range of emotions and reactions, ranging from complete ignorance to panic. Though it is included in the OWASP Top 10 list of web application security risks, at times vendors tend to downplay it and not treat it seriously.
As usual, the truth lies somewhere in between. What appears to be SSRF may sometimes in fact be intended functionality. Even so, an attacker may be able to abuse that functionality to improperly disclose sensitive information, either from the application containing the S
2023-04-11
Published