Tracker / CVE-2018-8426
CVE-2018-8426
Medium 5.4
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
Affected products and versions
| microsoft | sharepoint_enterprise_server_2013 |
|---|---|
| microsoft | sharepoint_enterprise_server_2016 |
| microsoft | sharepoint_server_2010 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.