CVE-2020-1320: XSS
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1320?
CVE-2020-1320 is rated as important, indicating a significant impact on the affected systems.
How do I fix CVE-2020-1320?
To mitigate CVE-2020-1320, it is recommended to apply the latest security updates provided by Microsoft for the affected versions of SharePoint.
Which versions are affected by CVE-2020-1320?
CVE-2020-1320 affects Microsoft SharePoint Server 2016, SharePoint Foundation 2010 (SP2), SharePoint Foundation 2013 (SP1), and SharePoint Server 2019.
What types of attacks does CVE-2020-1320 allow?
CVE-2020-1320 allows attackers to perform cross-site scripting (XSS) attacks, potentially compromising user information.
Can I still use affected SharePoint versions if I cannot patch CVE-2020-1320 immediately?
Using affected SharePoint versions without applying the patch for CVE-2020-1320 increases the risk of exploitation, so it's advisable to implement immediate risk mitigation strategies.