CVE-2020-1099: Microsoft Office SharePoint XSS Vulnerability
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.
Other sources
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4484332 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4484336
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker must be authenticated to an affected SharePoint server and able to send a specially crafted web request. Exploitation also requires a user to interact with the resulting cross-site scripting content.
What could a successful attack allow?
Script can run in the security context of the current user. This may let an attacker read content they are not authorized to access, act as the victim on the SharePoint site, including changing permissions or deleting content, and inject malicious browser content.
Which products are identified as affected?
The listed software includes Microsoft SharePoint Server, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server, and Microsoft SharePoint Enterprise Server 2016.
What addresses the vulnerability?
The security update addresses the issue by helping ensure that SharePoint Server properly sanitizes web requests.