{"api_version":"1","generated_at":"2026-05-01T11:31:55+00:00","cve":"CVE-2018-8300","urls":{"html":"https://cve.report/CVE-2018-8300","api":"https://cve.report/api/cve/CVE-2018-8300.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-8300","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-8300"},"summary":{"title":"CVE-2018-8300","description":"A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka \"Microsoft SharePoint Remote Code Execution Vulnerability.\" This affects Microsoft SharePoint.","state":"PUBLIC","assigner":"secure@microsoft.com","published_at":"2018-07-11 00:29:00","updated_at":"2019-06-10 13:45:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300","name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/104614","name":"104614","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Microsoft SharePoint Server CVE-2018-8300 Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1041261","name":"1041261","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Microsoft SharePoint Bugs Let Remote Users Execute Arbitrary Code and Remote Authenticated Users Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-8300","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8300","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"8300","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sharepoint_enterprise_server","cpe6":"2013","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"8300","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sharepoint_enterprise_server","cpe6":"2016","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"8300","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sharepoint_enterprise_server","cpe6":"2013","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"8300","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sharepoint_enterprise_server","cpe6":"2016","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2018-8300","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Microsoft SharePoint","version":{"version_data":[{"version_value":"Enterprise Server 2016"},{"version_value":"Foundation 2013 Service Pack 1"}]}}]},"vendor_name":"Microsoft"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka \"Microsoft SharePoint Remote Code Execution Vulnerability.\" This affects Microsoft SharePoint."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Code Execution"}]}]},"references":{"reference_data":[{"name":"104614","refsource":"BID","url":"http://www.securityfocus.com/bid/104614"},{"name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300","refsource":"CONFIRM","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8300"},{"name":"1041261","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1041261"}]}},"nvd":{"publishedDate":"2018-07-11 00:29:00","lastModifiedDate":"2019-06-10 13:45:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"8300","Ordinal":"124655","Title":"CVE-2018-8300","CVE":"CVE-2018-8300","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"8300","Ordinal":"1","NoteData":"A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka \"Microsoft SharePoint Remote Code Execution Vulnerability.\" This affects Microsoft SharePoint.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"8300","Ordinal":"2","NoteData":"2018-07-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"8300","Ordinal":"3","NoteData":"2018-07-11","Type":"Other","Title":"Modified"}]}}}