CVE-2019-0950 is a spoofing vulnerability affecting Microsoft SharePoint Server and SharePoint Foundation. It allows an attacker to spoof content by sending a specially crafted web request due to improper sanitization. Rated Medium severity with a CVSS score of 5.7, exploitation requires low privileges and user interaction, leading to high integrity impact but no confidentiality or availability impact. There is no public exploit code available, it is not on CISA's KEV catalog, and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.