First published: Wed Dec 12 2018(Updated: )
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Server | =2010-sp2 | |
Microsoft SharePoint Server | =2013-sp1 | |
Microsoft SharePoint Server | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8580 is classified as a moderate severity vulnerability affecting Microsoft SharePoint Server.
CVE-2018-8580 affects Microsoft SharePoint Server 2010 SP2, 2013 SP1, and 2016.
To mitigate CVE-2018-8580, apply the latest security updates provided by Microsoft for the affected SharePoint Server versions.
CVE-2018-8580 allows for cross-site search attacks, which can lead to information disclosure.
No, exploiting CVE-2018-8580 does not require user interaction, making it a significant risk.