CVE-2020-0693 is a medium-severity cross-site scripting (XSS) vulnerability affecting Microsoft SharePoint Server, stemming from improper sanitization of web requests. An attacker could exploit this with low complexity via a network attack, requiring user interaction and low privileges, potentially leading to limited disclosure of information and modification of data. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.