First published: Wed Jan 10 2018(Updated: )
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server 2016 | =2013-sp1 | |
Microsoft SharePoint Enterprise Server 2016 | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0799 is rated as a moderate severity vulnerability that can lead to cross-site scripting (XSS) attacks.
To fix CVE-2018-0799, ensure that you apply the latest security updates and patches provided by Microsoft for SharePoint Enterprise Server 2013 and 2016.
CVE-2018-0799 affects Microsoft SharePoint Enterprise Server versions 2013 SP1 and 2016.
CVE-2018-0799 is a cross-site scripting (XSS) vulnerability that arises from improper handling of image field values.
Yes, CVE-2018-0799 can be exploited remotely if an attacker can send a specially crafted request to the affected SharePoint server.