Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5r4c-r95m-h54g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data, aka 'Microsoft SharePoint Server Tampering Vulnerability'. This CVE ID is unique from CVE-2020-1523.

A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data, aka 'Microsoft SharePoint Server Tampering Vulnerability'. This CVE ID is unique from CVE-2020-1523.

EPSS

Процентиль: 82%
0.01772
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.3
nvd
больше 5 лет назад

<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user.</p> <p>The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.</p>

CVSS3: 6.3
msrc
больше 5 лет назад

Microsoft SharePoint Server Tampering Vulnerability

CVSS3: 4.3
fstec
больше 5 лет назад

Уязвимость пакетов программ Microsoft SharePoint Server, Microsoft SharePoint Foundation, Microsoft SharePoint Enterprise Server, связанная с недостаточной проверкой входных данных, позволяющая получить доступ на изменение данных

EPSS

Процентиль: 82%
0.01772
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20