CVE-2019-0558
Summary
| CVE | CVE-2019-0558 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-08 21:29:00 UTC |
| Updated | 2019-01-15 14:52:00 UTC |
| Description | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Business Productivity Servers | 2010 | sp2 | All | All |
| Application | Microsoft | Business Productivity Servers | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Office SharePoint CVE-2019-0558 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0558 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.