ZDI-20-1398: Microsoft SharePoint DataFormWebPart Server-Side Include Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft SharePoint Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of web parts of type DataFormWebPart. By specifying a custom DataFormWebPart, an attacker can cause the server to process arbitrary server-side includes. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-1398?
The severity of ZDI-20-1398 is classified as a medium risk due to the potential for sensitive information disclosure.
How do I fix ZDI-20-1398?
To fix ZDI-20-1398, apply the latest patches provided by Microsoft for SharePoint Server.
Who can exploit ZDI-20-1398?
ZDI-20-1398 requires authentication, meaning that only authenticated users can exploit this vulnerability.
What type of data is at risk with ZDI-20-1398?
ZDI-20-1398 can lead to the disclosure of sensitive information processed by affected SharePoint installations.
Which software is affected by ZDI-20-1398?
The affected software for ZDI-20-1398 includes Microsoft SharePoint Server.