ZDI-23-382: Microsoft SharePoint WSSXmlUrlResolver Server-Side Request Forgery Vulnerability
Published Apr 11, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Apr 11, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-382?
The severity of ZDI-23-382 is considered significant due to its potential for sensitive information disclosure.
2
How do I fix ZDI-23-382?
To fix ZDI-23-382, apply the latest security updates provided by Microsoft for SharePoint.
3
What type of attack does ZDI-23-382 enable?
ZDI-23-382 allows remote attackers to disclose sensitive information from affected Microsoft SharePoint installations.
4
Do I need authentication to exploit ZDI-23-382?
Yes, authentication is required to exploit the vulnerability ZDI-23-382.
5
Which software is affected by ZDI-23-382?
ZDI-23-382 affects installations of Microsoft SharePoint, specifically the 2013 version.