CVE-2018-8580: Infoleak
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8580?
CVE-2018-8580 is classified as a moderate severity vulnerability affecting Microsoft SharePoint Server.
What types of Microsoft SharePoint Server are affected by CVE-2018-8580?
CVE-2018-8580 affects Microsoft SharePoint Server 2010 SP2, 2013 SP1, and 2016.
How do I fix CVE-2018-8580?
To mitigate CVE-2018-8580, apply the latest security updates provided by Microsoft for the affected SharePoint Server versions.
What is the nature of the attack for CVE-2018-8580?
CVE-2018-8580 allows for cross-site search attacks, which can lead to information disclosure.
Is user interaction required to exploit CVE-2018-8580?
No, exploiting CVE-2018-8580 does not require user interaction, making it a significant risk.