First published: Thu May 21 2020(Updated: )
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server 2016 | =2016 | |
Microsoft SharePoint Foundation 2013 | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1103 is classified as a medium severity vulnerability.
To mitigate CVE-2020-1103, apply the latest security updates provided by Microsoft for SharePoint products.
CVE-2020-1103 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, and SharePoint Server 2019.
Attackers can exploit CVE-2020-1103 to gain unauthorized access to sensitive information via cross-site search attacks.
No, CVE-2020-1103 is a cross-site request forgery vulnerability rather than a cross-site scripting vulnerability.