Логотип exploitDog
bind:CVE-2017-11876
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-11876

Количество 3

Количество 3

nvd логотип

CVE-2017-11876

больше 7 лет назад

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2017-11876

больше 7 лет назад

Microsoft Project Server Elevation of Privilege Vulnerability

EPSS: Низкий
github логотип

GHSA-hc3g-h2rv-xpmc

около 3 лет назад

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-11876

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
msrc логотип
CVE-2017-11876

Microsoft Project Server Elevation of Privilege Vulnerability

1%
Низкий
больше 7 лет назад
github логотип
GHSA-hc3g-h2rv-xpmc

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".

CVSS3: 8.8
1%
Низкий
около 3 лет назад

Уязвимостей на страницу