CVE-2025-47172SQL Injection in Microsoft Sharepoint Enterprise Server 2016

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
4.1%
top 11.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5microsoft/microsoft_sharepoint_server_201916.0.016.0.10417.20018
CVEListV5microsoft/microsoft_sharepoint_enterprise_server_201616.0.016.0.5504.1001
CVEListV5microsoft/microsoft_sharepoint_server_subscription_edition16.0.016.0.18526.20396
NVDmicrosoft/sharepoint_server16.0.18526.20396+1

🔴Vulnerability Details

2
GHSA
GHSA-rq5m-6c4v-55rj: Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to e2025-06-10
CVEList
Microsoft SharePoint Server Remote Code Execution Vulnerability2025-06-10

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability2025-06-10
CVE-2025-47172 — SQL Injection in Microsoft | cvebase