CVE-2017-11876 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Microsoft Project Server and SharePoint Enterprise Server 2016. This flaw allows an attacker to read unauthorized content, perform actions on behalf of the victim (like changing permissions or deleting content), and inject malicious content into the victim's browser. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has received some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:project_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.