CVE-2019-1261High

Microsoft SharePoint Spoofing Vulnerability

Published
September 10, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF). To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes user web requests.

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2019

✅ Remediation

KB4475590 (Security Update) KB4475596 (Security Update) KB4484098 (Security Update)

🔗 References (7)