Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97xr-fxpc-2qp6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.

Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.

EPSS

Процентиль: 94%
0.14819
Средний

Дефекты

CWE-79

Связанные уязвимости

nvd
около 17 лет назад

Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.

EPSS

Процентиль: 94%
0.14819
Средний

Дефекты

CWE-79