CVE-2020-0894: XSS
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0893.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0894?
CVE-2020-0894 has a severity rating of important, indicating a moderate risk of exploitation.
How can I fix CVE-2020-0894?
To remediate CVE-2020-0894, apply the latest security updates provided by Microsoft for affected SharePoint versions.
What products are affected by CVE-2020-0894?
CVE-2020-0894 affects Microsoft SharePoint Server 2016, 2019 and SharePoint Foundation 2010 SP2 and 2013 SP1.
What type of vulnerability is CVE-2020-0894?
CVE-2020-0894 is classified as a cross-site scripting (XSS) vulnerability.
What kind of attacks can CVE-2020-0894 facilitate?
CVE-2020-0894 can facilitate attacks that allow attackers to execute arbitrary scripts in the context of the user's browser.