First published: Wed Sep 11 2019(Updated: )
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1259.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2019-1261 vulnerability has a severity rating of Moderate according to Microsoft.
To fix CVE-2019-1261, you should apply the latest security updates provided by Microsoft for the affected SharePoint versions.
CVE-2019-1261 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, and SharePoint Server 2019.
CVE-2019-1261 enables cross-site request forgery (CSRF) attacks due to improper handling of requests to authorize applications.
Yes, CVE-2019-1261 can be exploited remotely if an attacker creates a malicious page designed to issue unauthorized requests.