CVE-2019-1259Medium

Microsoft SharePoint Spoofing Vulnerability

Published
September 10, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF). To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes user web requests.

🎯 Affected products1

  • Microsoft SharePoint Foundation 2013 Service Pack 1

✅ Remediation

KB4484098 (Security Update)

🔗 References (3)