CVE-2020-1104 is a spoofing vulnerability in Microsoft SharePoint Server, SharePoint Foundation, and SharePoint Enterprise Server. It arises from improper sanitization of specially crafted web requests, allowing an attacker to spoof content. This vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack with low complexity, requiring user interaction and low privileges, potentially leading to limited impact on confidentiality and integrity. There is no evidence of active exploitation, nor are there known public exploits in Metasploit or ExploitDB. While it received some media coverage during the May 2020 Patch Tuesday, community discussion and exploit intelligence are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.