CVE-2020-1103 Information
Feb 14, 2021
cve
Description
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page the attacker can through standard browser functionality induce the browser to invoke search queries as the logged in user aka ‘Microsoft SharePoint Information Disclosure Vulnerability’.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1103
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: