CVE-2019-1032 is a medium-severity cross-site scripting (XSS) vulnerability affecting Microsoft SharePoint Server and SharePoint Enterprise Server. An authenticated attacker could exploit this by sending a specially crafted web request, allowing them to execute scripts in the current user's security context. This could lead to unauthorized content reading, actions on behalf of the user (like changing permissions or deleting content), and malicious content injection. The vulnerability has a CVSS score of 5.4, indicating a network-based attack with low complexity requiring user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.