TROYANOSYVIRUS
Volver a CVEs

CVE-2020-16942

MEDIUM
4.1

Descripcion

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.</p> <p>To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability.</p> <p>The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.</p>

Detalles CVE

Puntuacion CVSS v3.14.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueLOCAL
ComplejidadHIGH
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado10/16/2020
Ultima modificacion2/23/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

microsoft:sharepoint_enterprise_servermicrosoft:sharepoint_foundationmicrosoft:sharepoint_server

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.