Microsoft Office SharePoint CVE-2017-11820 Cross Site Scripting Vulnerability
BID:101097
CVE-2017-11820 |Info
Microsoft Office SharePoint CVE-2017-11820 Cross Site Scripting Vulnerability
| Bugtraq ID: | 101097 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-11820 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2017 12:00AM |
| Updated: | Oct 10 2017 12:00AM |
| Credit: | Andrew Watts & Adam Awan, eShare LtdCompany |
| Vulnerable: |
Microsoft SharePoint Enterprise Server 2016 0 Microsoft SharePoint Enterprise Server 2013 Service Pack 1 |
| Not Vulnerable: | |
Discussion
Microsoft Office SharePoint CVE-2017-11820 Cross Site Scripting Vulnerability
Microsoft Office SharePoint is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content on behalf of the victim on the SharePoint site.
Microsoft Office SharePoint is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content on behalf of the victim on the SharePoint site.
Exploit / POC
Microsoft Office SharePoint CVE-2017-11820 Cross Site Scripting Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].