Description
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Microsoft / Microsoft Business Productivity Servers2010 Service Pack 2 – 2010 Service Pack 2
- Microsoft / Microsoft SharePointEnterprise Server 2013 Service Pack 1 – Enterprise Server 2013 Service Pack 1
- Microsoft / Microsoft SharePointEnterprise Server 2016 – Enterprise Server 2016
- Microsoft / Microsoft SharePoint Server2019 – 2019