CVE-2018-8426 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010, 2013, and 2016. This medium-severity flaw (CVSS 5.4) allows an authenticated attacker to inject malicious scripts into a user's browser by crafting a special web request, leading to potential information disclosure and limited integrity impact. While no public exploit code or active exploitation has been observed, the vulnerability has received some community and media attention. Organizations should ensure their SharePoint installations are patched to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server_2013:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server_2016:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server_2010:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.