Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages4 packages
🔴Vulnerability Details
2CVEListMicrosoft SharePoint Information Disclosure Vulnerability↗2026-01-13 ▶ GHSAGHSA-m985-797h-4f3f: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network↗2026-01-13 ▶ 📋Vendor Advisories
1MicrosoftMicrosoft SharePoint Information Disclosure Vulnerability↗2026-01-13 ▶ 🕵️Threat Intelligence
1WizCVE-2026-20958 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶