CVE-2018-0799

Description

Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka Microsoft Access Tampering Vulnerability.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.791

Associated Vulnerability

VulnerabilityOS Platform
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft SharePoint Enterprise Server 2016 (KB4011642)Windows
Microsoft Access Tampering Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB4011599)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-23754Security Update for Microsoft SharePoint Enterprise Server 2016 (KB4011642)
PATCH-23751Security Update for Microsoft SharePoint Enterprise Server 2013 (KB4011599)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234