Логотип exploitDog
bind:CVE-2020-1103
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1103

Количество 4

Количество 4

nvd логотип

CVE-2020-1103

больше 5 лет назад

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-1103

больше 5 лет назад

Microsoft SharePoint Information Disclosure Vulnerability

EPSS: Низкий
github логотип

GHSA-88wv-c32x-w3h7

больше 3 лет назад

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

EPSS: Низкий
fstec логотип

BDU:2020-02477

больше 5 лет назад

Уязвимость пакетов программ Microsoft SharePoint Server, SharePoint Foundation и SharePoint Enterprise Server, связанная с некорректной обработкой запросов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-1103

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 6.5
9%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-1103

Microsoft SharePoint Information Disclosure Vulnerability

9%
Низкий
больше 5 лет назад
github логотип
GHSA-88wv-c32x-w3h7

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

9%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-02477

Уязвимость пакетов программ Microsoft SharePoint Server, SharePoint Foundation и SharePoint Enterprise Server, связанная с некорректной обработкой запросов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
9%
Низкий
больше 5 лет назад

Уязвимостей на страницу