CVE-2018-8580 is an information disclosure vulnerability in Microsoft SharePoint Server, specifically affecting certain modes of its search function. This flaw allows for cross-site search attacks, a variant of CSRF, to potentially leak sensitive information. Rated Medium severity (CVSS 4.3), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can be exploited over the network (AV:N). While there is no known public exploit code or active exploitation, it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:foundation:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:enterprise:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.