CVE-2018-0799: XSS
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0799?
CVE-2018-0799 is rated as a moderate severity vulnerability that can lead to cross-site scripting (XSS) attacks.
How do I fix CVE-2018-0799?
To fix CVE-2018-0799, ensure that you apply the latest security updates and patches provided by Microsoft for SharePoint Enterprise Server 2013 and 2016.
What systems are affected by CVE-2018-0799?
CVE-2018-0799 affects Microsoft SharePoint Enterprise Server versions 2013 SP1 and 2016.
What type of vulnerability is CVE-2018-0799?
CVE-2018-0799 is a cross-site scripting (XSS) vulnerability that arises from improper handling of image field values.
Can CVE-2018-0799 be exploited remotely?
Yes, CVE-2018-0799 can be exploited remotely if an attacker can send a specially crafted request to the affected SharePoint server.