ZDI-CAN-20748: ZDI-23-884: (Pwn2Own) Microsoft SharePoint userphoto Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft SharePoint. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20748?
The severity of ZDI-CAN-20748 is considered high due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-20748?
To fix ZDI-CAN-20748, apply the latest security updates provided by Microsoft for SharePoint.
What type of information can be disclosed through ZDI-CAN-20748?
ZDI-CAN-20748 allows the disclosure of sensitive information, which could include user credentials and configuration data.
Is authentication required to exploit ZDI-CAN-20748?
Yes, authentication is required to exploit ZDI-CAN-20748, but the existing mechanism can be bypassed.
Which software is affected by ZDI-CAN-20748?
ZDI-CAN-20748 affects installations of Microsoft SharePoint, specifically Microsoft SharePoint 2013.