CVE-2019-1259 is a high-severity spoofing vulnerability affecting Microsoft SharePoint Foundation, stemming from improper handling of application authorization requests, leading to Cross-Site Request Forgery (CSRF). With a CVSS score of 8.8, this vulnerability can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness. It is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.