Lucene search

K
cvelistMicrosoftCVELIST:CVE-2018-8580
HistoryDec 12, 2018 - 12:00 a.m.

CVE-2018-8580

2018-12-1200:00:00
microsoft
www.cve.org
1

4 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.3%

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka “Microsoft SharePoint Information Disclosure Vulnerability.” This affects Microsoft SharePoint.

CNA Affected

[
  {
    "product": "Microsoft SharePoint",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Enterprise Server 2013 Service Pack 1"
      },
      {
        "status": "affected",
        "version": "Enterprise Server 2016"
      },
      {
        "status": "affected",
        "version": "Foundation 2010 Service Pack 2"
      }
    ]
  }
]

4 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.3%