CVE-2019-0558 Information

Description

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server aka \Microsoft Office SharePoint XSS Vulnerability.\ This affects Microsoft SharePoint Server Microsoft SharePoint Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556 CVE-2019-0557.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

http://www.securityfocus.com/bid/106389 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0558

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: