
Cloud Vulnerability DB
A community-led vulnerabilities database
A cross-site-scripting (XSS) vulnerability identified as CVE-2020-0933 was discovered in Microsoft SharePoint Server. The vulnerability exists when the server fails to properly sanitize specially crafted web requests (NVD). This security issue was addressed in the April 14, 2020 security updates for various versions of SharePoint Server, including SharePoint Server 2019 and SharePoint Enterprise Server 2016 (Microsoft Support).
The vulnerability is caused by improper sanitization of web requests to affected SharePoint servers, which could allow cross-site scripting attacks (Microsoft Support).
If successfully exploited, this cross-site scripting vulnerability could allow an attacker to execute malicious scripts in the context of the affected SharePoint server (NVD).
Microsoft released security updates to address this vulnerability on April 14, 2020. The fixes are available through Microsoft Update, Microsoft Update Catalog, and Microsoft Download Center. For SharePoint Server 2019, users can apply security update 4484292, and for SharePoint Enterprise Server 2016, security update 4484299 is available (Microsoft Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."