CVE-2019-1261: CSRF
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1259.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1261?
The CVE-2019-1261 vulnerability has a severity rating of Moderate according to Microsoft.
How do I fix CVE-2019-1261?
To fix CVE-2019-1261, you should apply the latest security updates provided by Microsoft for the affected SharePoint versions.
What versions of SharePoint are affected by CVE-2019-1261?
CVE-2019-1261 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, and SharePoint Server 2019.
What type of attack does CVE-2019-1261 enable?
CVE-2019-1261 enables cross-site request forgery (CSRF) attacks due to improper handling of requests to authorize applications.
Can CVE-2019-1261 be exploited remotely?
Yes, CVE-2019-1261 can be exploited remotely if an attacker creates a malicious page designed to issue unauthorized requests.